QID 87500
Date Published: 2022-08-17
QID 87500: SAP NetWeaver AS ABAP and ABAP Platform Improper Authorization Vulnerability
The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786 allows an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an authenticated attacker used services that not to be allowed to see as normally.
Solution
Customers are advised to connect with vendors for further patch details.
Vendor References
- SAP Advisory -
launchpad.support.sap.com/#/notes/3112710
CVEs related to QID 87500
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Advisory |
|