QID 87450

Date Published: 2021-06-29

QID 87450: SAP NetWeaver AS ABAP Code Injection Vulnerability

SAP NetWeaver AS ABAP allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system.

Affected Versions:
SAP NetWeaver AS ABAP Versions - 700,701,702,730,731

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

The attacker could then get access to data, overwrite them, or execute a denial of service.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3046610 for remediation instructions.
    Vendor References

    CVEs related to QID 87450

    Software Advisories
    Advisory ID Software Component Link
    SAP Security Note 3046610 URL Logo launchpad.support.sap.com/#/notes/3046610