QID 87531
Date Published: 2023-03-08
QID 87531: SAP NetWeaver AS ABAP and ABAP Multiple Vulnerabilities
SAP NetWeaver AS ABAP and ABAP Platform affected by multiple vulnerabilities.
CVE-2023-23860- allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack.
CVE-2023-23859- allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to cause impact on confidentiality and integrity of the application.
- SAP Security Advisory February 2023 -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87531
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory February 2023 |
|