QID 87512

Date Published: 2022-08-22

QID 87512: SAP NetWeaver AS for Java Information Disclosure Vulnerability

SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.

Affected Versions
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploit may lead to Sensitive Information Disclosure

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to follow the SAP Security Advisory for remediation instructions.
    Vendor References

    CVEs related to QID 87512

    Software Advisories
    Advisory ID Software Component Link
    3059764 URL Logo launchpad.support.sap.com/#/notes/3059764