Files
CVEs-PoC/2017/CVE-2017-16679.md
T
2025-09-29 21:09:30 +02:00

18 lines
1.0 KiB
Markdown

### [CVE-2017-16679](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16679)
![](https://img.shields.io/static/v1?label=Product&message=SAP%20Startup%20Service&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=SAP%20KERNEL%2032%20NUC%2C%20SAP%20KERNEL%2032%20Unicode%2C%20SAP%20KERNEL%2064%20NUC%2C%20SAP%20KERNEL%2064%20Unicode%207.21%2C%207.21EXT%2C%207.22%20and%207.22EXT%3B%20SAP%20KERNEL%207.21%2C%207.22%2C%207.45%2C%207.49%20and%207.52.%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=URL%20Redirection&color=brightgreen)
### Description
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.52, that allows an attacker to redirect users to a malicious site.
### POC
#### Reference
- https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/
#### Github
No PoCs found on GitHub currently.