QID 87446
Date Published: 2021-04-08
QID 87446: SAP NetWeaver AS JAVA Directory Traversal Vulnerability
SAP NetWeaver Application Server (AS) or SAP Web Application Server is a component of the solution which works as a web application server to SAP solutions.
SAP NetWeaver AS JAVA is exposed to a directory traversal vulnerability. (CVE-2016-3976)
Affected Versions
SAP NetWeaver AS JAVA Versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40 , 7.50.
QID Detection Logic(s):
Scan initiates HTTP request with an active payload to detect the vulnerability.
A successful exploit could give an unauthenticated attacker access file on the SAP system.
Solution
Customers are advised to follow the SAP Security Patch Day - March 2016 for remediation instructions.
Vendor References
- SAP Security Patch Day - March 2016 -
blogs.sap.com/2016/03/08/sap-security-patch-day-march-2016/
CVEs related to QID 87446
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Notes March 2016 - Review |
|