PT-2021-14541 · Sap · Sap Netweaver As Abap+1

Alexander Meier

+1

·

Published

2021-06-09

·

Updated

2022-10-05

·

CVE-2021-21473

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS ABAP and ABAP Platform versions 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755
Description The issue is related to the function module SRM RFC SUBMIT REPORT which fails to validate authorization of an authenticated user, thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.
Recommendations For SAP NetWeaver AS ABAP and ABAP Platform versions 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, consider disabling the SRM RFC SUBMIT REPORT function module as a temporary workaround until a patch is available. Restrict access to the SRM RFC SUBMIT REPORT function module to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-21473

Affected Products

Abap Platform
Sap Netweaver As Abap