QID 87488

Date Published: 2022-03-28

QID 87488: SAP NetWeaver AS for Java Information Disclosure Vulnerability

SAP NetWeaver AS JAVA (Telnet Commands), versions - 7.10, 7.11, 7.20, 7. 30, 7.31, 7.40, 7.50, may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.

Affected Versions
SAP NetWeaver AS for JAVA (Telnet Commands), Versions - 7.10, 7.11, 7.20, 7. 30, 7.31, 7.40, 7.50

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploit may lead to Information Disclosure

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 3001824 for remediation instructions.

    CVEs related to QID 87488

    Software Advisories
    Advisory ID Software Component Link
    3001824 URL Logo wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649