QID 87449
Date Published: 2021-06-23
QID 87449: SAP NetWeaver AS ABAP Missing Authorization Vulnerability
SAP NetWeaver AS ABAP and ABAP Platform contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.
Affected Versions:
SAP NetWeaver AS ABAP and ABAP Platform Versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation may allow an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.
Solution
Customers are advised to follow the SAP Security Note 3002517 for remediation instructions.
Vendor References
- SAP Security Note 3002517 -
wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999
CVEs related to QID 87449
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Note 3002517 |
|