QID 87517
Date Published: 2022-08-22
QID 87517: SAP NetWeaver AS for Java Arbitrary File Upload Vulnerability.
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.
Affected Versions
SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to upload arbitrary file on the target system.
Solution
Customers are advised to follow the SAP Security Advisory for remediation instructions.
Vendor References
CVEs related to QID 87517
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2974330 |
|