QID 87534
Date Published: 2023-03-08
QID 87534: SAP NetWeaver AS ABAP and ABAP Uniform Resource Locator (URL) Redirection Vulnerability
SAP NetWeaver AS ABAP and ABAP Platform affected by URL Redirection.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions -700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to cause impact on confidentiality and integrity of the application.
Solution
Customers are advised to follow the SAP Security Advisory February 2023 for remediation instructions.
Vendor References
- SAP Security Advisory February 2023 -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87534
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory February 2023 |
|