QID 87469

Date Published: 2021-10-29

QID 87469: SAP NetWeaver AS ABAP and ABAP Platform Improper Authorization Vulnerability

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the confidentiality, integrity, and availability of the system and its data.

Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3097887 for remediation instructions.

    CVEs related to QID 87469

    Software Advisories
    Advisory ID Software Component Link
    SAP Security Note 3097887 URL Logo wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983