QID 87485

Date Published: 2022-02-28

QID 87485: SAP NetWeaver ABAP Cross-Site Scripting (XSS) Vulnerability (3124994)

The software logistics system of SAP NetWeaver AS ABAP versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756 allows to inject code that may expose sensitive data like user ID and password.

Affected Versions:
SAP NetWeaver AS ABAP, Versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

successful exploitation can partially impact confidentiality of the application.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3124994 for remediation instructions.

    CVEs related to QID 87485

    Software Advisories
    Advisory ID Software Component Link
    3124994 URL Logo dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10