QID 87501

Date Published: 2022-08-17

QID 87501: SAP NetWeaver AS ABAP and ABAP Platform Information Disclosure Vulnerability

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 740, 750, 787 allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.

Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 740, 750, 787

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to disclose personal information.

  • CVSS V3 rated as Medium - 4.7 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to follow the SAP Security Advisory for remediation instructions.

    CVEs related to QID 87501

    Software Advisories
    Advisory ID Software Component Link
    SAP Advisory URL Logo www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html