QID 87450
Date Published: 2021-06-29
QID 87450: SAP NetWeaver AS ABAP Code Injection Vulnerability
SAP NetWeaver AS ABAP allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system.
Affected Versions:
SAP NetWeaver AS ABAP Versions - 700,701,702,730,731
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
The attacker could then get access to data, overwrite them, or execute a denial of service.
Solution
Customers are advised to follow the SAP Security Note 3046610 for remediation instructions.
Vendor References
- SAP Security Note 3046610 -
launchpad.support.sap.com/#/notes/3046610
CVEs related to QID 87450
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Note 3046610 |
|