SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Netweaver_as_abap_kernel | Sap | 7.22 (including) | 7.22 (including) |
| Netweaver_as_abap_kernel | Sap | 7.53 (including) | 7.53 (including) |
| Netweaver_as_abap_kernel | Sap | 7.54 (including) | 7.54 (including) |
| Netweaver_as_abap_kernel | Sap | 7.77 (including) | 7.77 (including) |
| Netweaver_as_abap_kernel | Sap | 7.89 (including) | 7.89 (including) |
| Netweaver_as_abap_kernel | Sap | 7.93 (including) | 7.93 (including) |
| Netweaver_as_abap_kernel | Sap | 9.16 (including) | 9.16 (including) |
| Netweaver_as_abap_kernel | Sap | 9.18 (including) | 9.18 (including) |
| Netweaver_as_abap_kernel | Sap | 9.19 (including) | 9.19 (including) |
| Netweaver_as_abap_krnl64nuc | Sap | 7.22 (including) | 7.22 (including) |
| Netweaver_as_abap_krnl64nuc | Sap | 7.22ext (including) | 7.22ext (including) |
| Netweaver_as_abap_krnl64uc | Sap | 7.22 (including) | 7.22 (including) |
| Netweaver_as_abap_krnl64uc | Sap | 7.22ext (including) | 7.22ext (including) |
| Netweaver_as_abap_krnl64uc | Sap | 7.53 (including) | 7.53 (including) |