QID 87492
Date Published: 2022-07-05
QID 87492: SAP NetWeaver AS SQL Injection Vulnerability
SAP NetWeaver is a technology platform that allows organizations to integrate data, business processes, elements and more from a variety of sources into unified SAP environments.
Affected Versions
SAP NetWeaver J2EE Engine Versions - 7.40
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
It allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Solution
Customers are advised to follow the CVE-2016-2386 for remediation instructions.
Vendor References
- CVE-2016-2386 -
nvd.nist.gov/vuln/detail/CVE-2016-2386
CVEs related to QID 87492
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2101079 |
|