PT-2021-17539 · Sap · Sap Netweaver As Abap
Published
2021-04-13
·
Updated
2022-10-05
·
CVE-2021-27603
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS ABAP versions 731, 740, 750
Description
The issue allows an attacker to cause a Denial of Service, affecting the Availability of the SAP system by blocking all work processes. This is achieved by calling the
SPI WAIT MILLIS function module multiple times, keeping a work process busy for any length of time.Recommendations
For versions 731, 740, 750, consider restricting access to the
SPI WAIT MILLIS function module to prevent its misuse and minimize the risk of Denial of Service attacks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Netweaver As Abap