QID 87494

Date Published: 2022-07-05

QID 87494: SAP NetWeaver AS File Upload Vulnerability

SAP NetWeaver is a technology platform that allows organizations to integrate data, business processes, elements and more from a variety of sources into unified SAP environments.

Affected Versions
SAP NetWeaver J2EE Engine Versions - 7.30, 7.31, 7.40, 7.50

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to follow the SAP Security Note 2256846 for remediation instructions.

    CVEs related to QID 87494

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-38163 URL Logo wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405