A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. “eval”).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netweaver_application_server_abap | Sap | 75a (including) | 75a (including) |
Netweaver_application_server_abap | Sap | 75b (including) | 75b (including) |
Netweaver_application_server_abap | Sap | 75c (including) | 75c (including) |
Netweaver_application_server_abap | Sap | 75d (including) | 75d (including) |
Netweaver_application_server_abap | Sap | 75e (including) | 75e (including) |
Netweaver_application_server_abap | Sap | 75f (including) | 75f (including) |
Netweaver_application_server_abap | Sap | 700 (including) | 700 (including) |
Netweaver_application_server_abap | Sap | 701 (including) | 701 (including) |
Netweaver_application_server_abap | Sap | 702 (including) | 702 (including) |
Netweaver_application_server_abap | Sap | 710 (including) | 710 (including) |
Netweaver_application_server_abap | Sap | 711 (including) | 711 (including) |
Netweaver_application_server_abap | Sap | 730 (including) | 730 (including) |
Netweaver_application_server_abap | Sap | 731 (including) | 731 (including) |
Netweaver_application_server_abap | Sap | 740 (including) | 740 (including) |
Netweaver_application_server_abap | Sap | 750 (including) | 750 (including) |
Netweaver_application_server_abap | Sap | 751 (including) | 751 (including) |
Netweaver_application_server_abap | Sap | 752 (including) | 752 (including) |