QID 87493
Date Published: 2022-07-05
QID 87493: SAP NetWeaver AS Exposure of Sensitive Information Vulnerability
SAP NetWeaver is a technology platform that allows organizations to integrate data, business processes, elements and more from a variety of sources into unified SAP environments.
Affected Versions
SAP NetWeaver J2EE Engine Versions - 7.10-7.50
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
It allows remote attackers to obtain sensitive user information via a crafted HTTP request.
Solution
Customers are advised to follow the CVE-2016-2388 for remediation instructions.
Vendor References
- CVE-2016-2388 -
nvd.nist.gov/vuln/detail/CVE-2016-2388
CVEs related to QID 87493
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2256846 |
|