QID 87545
Date Published: 2023-06-26
QID 87545: SAP NetWeaver AS for ABAP and ABAP Platform Capture-replay Vulnerability
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757 are prone to Capture-replay vulnerability
Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757
Note: added for ABAP platform only, making pratice since banner based detection
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
Solution
Customers are advised to follow the SAP NetWeaver AS for ABAP and ABAP Platform for remediation instructions.
Vendor References
- SAP Security Advisory -
www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
CVEs related to QID 87545
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAP Security Advisory |
|