QID 87532
Date Published: 2023-03-08
QID 87532: SAP NetWeaver AS ABAP and ABAP Cross-Site Scripting (XSS) Vulnerability
SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions -700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
This may lead to a limited impact on the confidentiality and the integrity of the application.
Solution
Customers are advised to follow the SAP Security Advisory February 2023 for remediation instructions.
Vendor References
- SAP Security Advisory February 2023 -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87532
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory February 2023 |
|