SAP NetWeaver AS Java Information Disclosure (Enterprise Portal) (3059764)

medium Nessus Plugin ID 162414

Synopsis

The remote SAP NetWeaver AS Java server may be affected by a information disclosure vulnerability.

Description

SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Apply the appropriate patch according to the vendor advisory.

See Also

https://launchpad.support.sap.com/#/notes/3059764

http://www.nessus.org/u?39f0ff28

Plugin Details

Severity: Medium

ID: 162414

File Name: sap_netweaver_as_java_3059764.nasl

Version: 1.2

Type: remote

Family: Web Servers

Published: 6/21/2022

Updated: 6/22/2022

Configuration: Enable paranoid mode

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS Score Source: CVE-2021-33687

CVSS v3

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:2.3:a:sap:netweaver_application_server:*:*:*:*:*:*:*:*

Required KB Items: Settings/ParanoidReport, installed_sw/SAP Netweaver Application Server (AS)

Exploit Ease: No known exploits are available

Patch Publication Date: 7/13/2021

Vulnerability Publication Date: 7/13/2021

Reference Information

CVE: CVE-2021-33687

IAVA: 2021-A-0310