QID 87545

Date Published: 2023-06-26

QID 87545: SAP NetWeaver AS for ABAP and ABAP Platform Capture-replay Vulnerability

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757 are prone to Capture-replay vulnerability

Affected Versions:
SAP NetWeaver AS for ABAP, Versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757

Note: added for ABAP platform only, making pratice since banner based detection

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to follow the SAP NetWeaver AS for ABAP and ABAP Platform for remediation instructions.

    CVEs related to QID 87545

    Software Advisories
    Advisory ID Software Component Link
    SAP Security Advisory URL Logo www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html