QID 87459
Date Published: 2021-08-12
QID 87459: SAP NetWeaver AS Java Remote Code Execution Vulnerability
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file..
Affected Versions
SAP NetWeaver AS JAVA Versions 7.20, 7.30, 7.31, 7.40, 7.50
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary commands on the target system.
Solution
Customers are advised to follow the SAP Security Note 2979062 for remediation instructions.
Vendor References
- SAP Security Note 2979062 -
wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571
CVEs related to QID 87459
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2979062 |
|