QID 87453

Date Published: 2021-07-01

QID 87453: SAP NetWeaver (ABAP Server) and ABAP Platform Improper Authentication Vulnerability

SAP NetWeaver AS ABAP and ABAP Platform contains Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform.

Affected Versions:
SAP NetWeaver AS ABAP and ABAP Platform Versions - 700,701,702,731,740,750,751,752,753,754,755,804

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation may allow an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3007182 for remediation instructions.
    Vendor References

    CVEs related to QID 87453

    Software Advisories
    Advisory ID Software Component Link
    SAP Security note 3007182 URL Logo launchpad.support.sap.com/#/notes/3007182