PT-2021-14548 · Sap · Sap Netweaver Master Data Management

Published

2021-04-13

·

Updated

2021-04-21

·

CVE-2021-21482

CVSS v3.1

8.3

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Master Data Management versions 710 through 710.750
Description The issue allows a malicious unauthorized user with access to the MDM Server subnet to potentially find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges, leading to information disclosure and affecting the confidentiality and integrity of the application. This occurs when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.
Recommendations For SAP NetWeaver Master Data Management versions 710 through 710.750, ensure that security guidelines and recommendations concerning administrative accounts are thoroughly reviewed and implemented to prevent brute force attacks on passwords. Consider temporarily restricting access to administrative privileges until the security guidelines are fully implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-21482

Affected Products

Sap Netweaver Master Data Management