QID 87499

Date Published: 2022-08-17

QID 87499: SAP NetWeaver AS ABAP and ABAP Platform Privilege Escalation Vulnerability

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, 788 do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, 788

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation of this vulnerability may allow a low privileged attacker to escalate itself to high privileges.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to follow the SAP Security Advisory for remediation instructions.

    CVEs related to QID 87499

    Software Advisories
    Advisory ID Software Component Link
    SAP Advisory URL Logo www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html