SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HSap Netweaver Application Server Abap
APPSap700701702710711730731740750751752753754755756+ 1 moreSap Netweaver Application Server Abap Kernel
APPSap7.227.537.777.817.857.89Sap Netweaver Application Server Abap Krnl64nuc
APPSap7.227.22extSap Netweaver Application Server Abap Krnl64uc
APPSap7.227.22ext7.53
Related vulnerabilities
Request Smuggling w SAP NetWeaver i SAP Web Dispatcher — CVSS 10.0
SAP CRM / S/4HANA Scripting Editor — nieautoryzowane wykonanie SQL
SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation
SAP NetWeaver AS ABAP — path traversal umożliwia nadpisanie plików systemowych
SAP NetWeaver AS ABAP: path traversal w SAPRSBRO umożliwia nadpisanie plików systemowych