VYPR
Medium severity6.1NVD Advisory· Published Nov 8, 2022· Updated Jun 17, 2026

CVE-2022-41207

CVE-2022-41207

Description

SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or modification of the victim's information.

Affected products

4
  • SAP/Biller Direct3 versions
    cpe:2.3:a:sap:biller_direct:635:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:biller_direct:635:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:biller_direct:750:*:*:*:*:*:*:*
    • (no CPE)
  • SAP SE/SAP Biller Directv5
    Range: = 635

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.