QID 87484
Date Published: 2022-02-24
QID 87484: SAP NetWeaver AS ABAP SQL Injection Vulnerability (3140587)
The software logistics system of SAP NetWeaver AS ABAP versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787 allows an attacker to execute crafted database queries, that could expose the backend database
Affected Versions:
SAP NetWeaver AS ABAP, Versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation could result in disclosure of a table of contents from the system
Solution
Customers are advised to follow the SAP Security Note 3140587 for remediation instructions.
Vendor References
CVEs related to QID 87484
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 3140587 |
|