QID 87484

Date Published: 2022-02-24

QID 87484: SAP NetWeaver AS ABAP SQL Injection Vulnerability (3140587)

The software logistics system of SAP NetWeaver AS ABAP versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787 allows an attacker to execute crafted database queries, that could expose the backend database

Affected Versions:
SAP NetWeaver AS ABAP, Versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation could result in disclosure of a table of contents from the system

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3140587 for remediation instructions.

    CVEs related to QID 87484

    Software Advisories
    Advisory ID Software Component Link
    3140587 URL Logo wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022