QID 87485
Date Published: 2022-02-28
QID 87485: SAP NetWeaver ABAP Cross-Site Scripting (XSS) Vulnerability (3124994)
The software logistics system of SAP NetWeaver AS ABAP versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756 allows to inject code that may expose sensitive data like user ID and password.
Affected Versions:
SAP NetWeaver AS ABAP, Versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
successful exploitation can partially impact confidentiality of the application.
Solution
Customers are advised to follow the SAP Security Note 3124994 for remediation instructions.
Vendor References
CVEs related to QID 87485
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 3124994 |
|