QID 87498

Date Published: 2022-08-22

QID 87498: SAP NetWeaver AS ABAP and ABAP Platforms Information Disclosure Vulnerability

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756 allows a high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls.

Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation of this vulnerability may allows a high privileged user to read connection details.

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to connect with vendor for patch details.
    Vendor References

    CVEs related to QID 87498

    Software Advisories
    Advisory ID Software Component Link
    SAP Advisory URL Logo launchpad.support.sap.com/#/notes/3128473