QID 87495
Date Published: 2022-07-11
QID 87495: SAP NetWeaver AS Server-Side Request Forgery Vulnerability
SAP NetWeaver is a technology platform that allows organizations to integrate data, business processes, elements and more from a variety of sources into unified SAP environments.
Affected Versions
SAP NetWeaver AS JAVA -7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
It allows remote attackers to send a crafted request from a vulnerable web application resulting in a Server-Side Request Forgery vulnerability..
Solution
Customers are advised to follow the 2896025 for remediation instructions.
Vendor References
- CVE-2020-6282 -
wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
CVEs related to QID 87495
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2896025 |
|