QID 87529
Date Published: 2023-01-17
QID 87529: SAP NetWeaver AS ABAP and ABAP Cross-Site Scripting (XSS) Vulnerability
SAP NetWeaver AS ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to cause limited impact on confidentiality and integrity of the application.
Solution
Customers are advised to follow the SAP Security Advisory January 2023 for remediation instructions.
Vendor References
- SAP Security Advisory January 2023 -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87529
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory January 2023 |
|