QID 87537

Date Published: 2023-03-20

QID 87537: SAP NetWeaver AS for ABAP and ABAP Platform Multiple Vulnerabilities

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, and 791 are prone to multiple vulnerabilities as listed in SAP NetWeaver AS for ABAP and ABAP Platform

Affected Versions:
SAP NetWeaver AS for ABAP, Versions -700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, and 791

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation of these vulnerabilities may allow an attacker to compromise confidentiality and integrity of the application.

  • CVSS V3 rated as Critical - 9.6 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Customers are advised to follow the SAP NetWeaver AS for ABAP and ABAP Platform for remediation instructions.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SAP Security Advisory March 2023 URL Logo www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html