QID 87526
Date Published: 2022-12-28
QID 87526: SAP NetWeaver AS ABAP and ABAP Platform Security Update (3256571)
SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 700, 731, 804, 740, 750, 789
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to completely compromise the integrity and availability of the application.
Solution
Customers are advised to follow the SAP Security Advisory for remediation instructions.
Vendor References
- SAP Security Advisory -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87526
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory |
|