QID 87512
Date Published: 2022-08-22
QID 87512: SAP NetWeaver AS for Java Information Disclosure Vulnerability
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
Affected Versions
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploit may lead to Sensitive Information Disclosure
Solution
Customers are advised to follow the SAP Security Advisory for remediation instructions.
Vendor References
CVEs related to QID 87512
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 3059764 |
|