#VU78731 Improper Neutralization of HTTP Headers for Scripting Syntax in SAP Solution Manager - CVE-2023-36921
Published: July 27, 2023
SAP Solution Manager
SAP
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper input validation when processing HTTP requests in diagnostic agent. A remote non-authenticated attacker can send a specially crafted HTTP request with an arbitrary header that will be accepted by the application.
Successful exploitation of the vulnerability may allow an attacker to perform cross-site scripting, cache poisoning or session hijacking attacks.