QID 87462

Date Published: 2021-09-27

QID 87462: SAP NetWeaver AS Java Improper Access Control Vulnerability

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.

Affected Versions
SAP NetWeaver AS for JAVA (Customer Usage Provisioning Servlet), Versions - 7.31, 7.40, 7.50

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

This vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3027937 for remediation instructions.
    Vendor References

    CVEs related to QID 87462

    Software Advisories
    Advisory ID Software Component Link
    3027937 URL Logo wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649