Medium severity6.1NVD Advisory· Published Apr 14, 2020· Updated Jun 17, 2026
CVE-2020-6215
CVE-2020-6215
Description
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- SAP SE/SAP NetWeaver AS ABAP (Business Server Pages Test Application IT00)v5Range: < 700
- Range: 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754
- Range: 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754
cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:700:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:701:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:702:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:730:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:750:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:751:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:752:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:754:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- packetstormsecurity.com/files/174985/SAP-Application-Server-ABAP-Open-Redirection.htmlnvd
- seclists.org/fulldisclosure/2023/Oct/13nvd
News mentions
0No linked articles in our index yet.