QID 87475

Date Published: 2021-12-20

QID 87475: SAP NetWeaver AS ABAP and ABAP Platform Denial of Service (DoS) Vulnerability (3099011)

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 740, 750, 751, 752, 753, 754, 755 allows an unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP NetWeaver Application Server ABAP and ABAP Platform.

Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 740, 750, 751, 752, 753, 754, 755

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation of this vulnerability may allow an attacker to perform Denial of Service attack on the target system.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3099011 for remediation instructions.

    CVEs related to QID 87475

    Software Advisories
    Advisory ID Software Component Link
    3099011 URL Logo wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983