QID 87475
Date Published: 2021-12-20
QID 87475: SAP NetWeaver AS ABAP and ABAP Platform Denial of Service (DoS) Vulnerability (3099011)
The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 740, 750, 751, 752, 753, 754, 755 allows an unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP NetWeaver Application Server ABAP and ABAP Platform.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 740, 750, 751, 752, 753, 754, 755
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to perform Denial of Service attack on the target system.
Solution
Customers are advised to follow the SAP Security Note 3099011 for remediation instructions.
Vendor References
CVEs related to QID 87475
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 3099011 |
|