SAP NetWeaver Application Server for ABAP
cpe:2.3:a:sap:netweaver_application_server_for_abap:*:*:*:*:*:*:*, +1 more
A Cross-Site Request Forgery (CSRF) vulnerability exists in SAP NetWeaver Application Server for ABAP. This vulnerability allows an authenticated attacker to initiate transactions directly through the session manager, bypassing the initial transaction screen and the necessary authorization checks. As a result, the attacker could access and execute transactions that typically require specific permissions, thereby compromising the system's integrity and confidentiality by enabling unauthorized access to restricted functions. However, this vulnerability does not affect the system's availability.
Exploitation of this vulnerability could lead to unauthorized access and actions within the system, allowing attackers to perform transactions and access functionalities that require specific permissions.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where users can find the complete list of security notes and prioritize their implementation. For SAP NetWeaver products, security fixes are also included in the regular support package updates.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.