S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 6, 2024

CVE-2005-3634 Scanner

CVE-2005-3634 scanner - Open Redirect vulnerability in SAP Web Application Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2005-3634
5.0
CVSS

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

SAP Web Application Server (WAS) is an enterprise-level software platform designed to support business-critical applications and services. It is intended to facilitate a variety of tasks such as data processing, transaction management, and complex processing workflows. The software is widely used by large organizations across various industries, including banking, finance, healthcare, and manufacturing.

One of the security vulnerabilities that was detected in SAP WAS is CVE-2005-3634. This vulnerability allows malicious attackers to log users out remotely and redirect them to arbitrary websites by leveraging the frameset.htm function in the BSP runtime. Exploiting this flaw requires the attacker to use the "close" command in the sap-sessioncmd parameter and the "sap-exiturl" parameter to specify the desired URL.

The exploitation of the CVE-2005-3634 vulnerability could lead to severe consequences. Attackers can redirect users to phishing websites, where they could cause them to disclose sensitive information. Alternatively, the attackers can download malicious software onto the user's device, leading to data theft, ransomware attacks, and other malicious activities.

Finally, s4e.io offers a range of pro features that help businesses scan and identify vulnerabilities in their digital assets quickly and easily. By using the platform, users can gain insights into potential threats and take measures to prevent data breach incidents. The pro features also provide users with comprehensive reporting, trend analysis, and customized notifications for actionable insights. With s4e.io, businesses can stay ahead of cybercriminals and protect their digital assets.

 

REFERENCES

Solution Advice

To protect against the CVE-2005-3634 vulnerability, the following precautions should be taken:

  • Implement regular software updates and patches to prevent the exploitation of known vulnerabilities.
  • Enforce network segmentation to limit access to sensitive systems and data.
  • Monitor inbound and outbound network traffic to detect and block malicious actions.
  • Enable multi-factor authentication to prevent unauthorized access to critical systems.
  • Train employees on cybersecurity best practices such as avoiding suspicious links and emails.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2005-3634 scanner - Open Redirect vulnerability in SAP Web Application Server | S4E