QID 87518

Date Published: 2022-09-05

QID 87518: SAP NetWeaver AS for Java Security Update (3038594)

When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.

Affected Versions
SAP NetWeaver AS JAVA, versions - 7.50

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation of this vulnerability may affect the Integrity.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to follow the SAP Security Advisory for remediation instructions.
    Vendor References

    CVEs related to QID 87518

    Software Advisories
    Advisory ID Software Component Link
    3038594 URL Logo launchpad.support.sap.com/#/notes/3038594