Back to results

SAP BTP - Critical vulnerability finding in custom app

Identifies SAP BTP Application Vulnerability Report Service findings where the CVSS score exceeds a configurable threshold (default 9.0, i.e. Critical severity). Such findings indicate custom applications deployed on…

Description

Identifies SAP BTP Application Vulnerability Report Service findings where the CVSS score exceeds a configurable threshold (default 9.0, i.e. Critical severity). Such findings indicate custom applications deployed on SAP BTP that carry vulnerable open-source packages or components with a known, high-impact CVE. These risky applications should be prioritized for remediation and reviewed for signs of exploitation.

Detection logic

Detection requirements

Platform
ContainersESXiIaaSLinuxmacOSNetwork DevicesWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source product
sapbtpavl
Log source service
sapbtpavl_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice