QID 87536
Date Published: 2023-03-08
QID 87536: SAP NetWeaver AS ABAP and ABAP Privilege Escalation Vulnerability
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Affected Versions:
SAP NetWeaver AS for ABAP, Versions -700, 701, 702, 731, 740, 750, 751, 752
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to cause impact on confidentiality and integrity of the application.
Solution
Customers are advised to follow the CVE-2023-23854 for remediation instructions.
Vendor References
- SAP Security Advisory February 2023 -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87536
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory February 2023 |
|