PT-2021-14548 · Sap · Sap Netweaver Master Data Management
Published
2021-04-13
·
Updated
2021-04-21
·
CVE-2021-21482
CVSS v3.1
8.3
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Master Data Management versions 710 through 710.750
Description
The issue allows a malicious unauthorized user with access to the MDM Server subnet to potentially find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges, leading to information disclosure and affecting the confidentiality and integrity of the application. This occurs when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.
Recommendations
For SAP NetWeaver Master Data Management versions 710 through 710.750, ensure that security guidelines and recommendations concerning administrative accounts are thoroughly reviewed and implemented to prevent brute force attacks on passwords. Consider temporarily restricting access to administrative privileges until the security guidelines are fully implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Netweaver Master Data Management