Inconsistent interpretation of HTTP requests in SAP Web Dispatcher Kernel and SAP Web Dispatcher WEBDISP - CVE-2023-33987
Published: July 27, 2023
SAP Web Dispatcher Kernel
SAP Web Dispatcher WEBDISP
SAP
Description
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.