SAP BTP - Critical vulnerability finding in custom app
Identifies SAP BTP Application Vulnerability Report Service findings where the CVSS score exceeds a configurable threshold (default 9.0, i.e. Critical severity). Such findings indicate custom applications deployed on…
Description
Identifies SAP BTP Application Vulnerability Report Service findings where the CVSS score exceeds a configurable threshold (default 9.0, i.e. Critical severity). Such findings indicate custom applications deployed on SAP BTP that carry vulnerable open-source packages or components with a known, high-impact CVE. These risky applications should be prioritized for remediation and reviewed for signs of exploitation.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSLinuxmacOSNetwork DevicesWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source product
- sapbtpavl
- Log source service
- sapbtpavl_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- 8a4c9e2f-6b1d-4e7a-9c3f-2d5b8f1a6e4c
- Tagged by the source as
- InitialAccess
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 2, 2026
- Version
- 1