QID 87544
Date Published: 2023-06-06
QID 87544: SAP NetWeaver ABAP Directory Traversal Vulnerability
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server.
Affected Versions:
SAP NetWeaver for ABAP Versions - 707, 737, 747, 757
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of these vulnerabilities may may lead to a high impact on the availability and integrity of the application.
Solution
Customers are advised to follow the SAP NetWeaver ABAP for remediation instructions.
Vendor References
- SAP Security Advisory April 2023 -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87544
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory April 2023 |
|