PT-2021-17546 · Sap · Sap Netweaver As Abap

Published

2021-05-11

·

Updated

2022-10-05

·

CVE-2021-27611

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS ABAP versions 700, 701, 702, 730, 731
Description The issue allows a high-privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. This could lead to unauthorized access to data, data overwrite, or execution of a denial of service.
Recommendations For SAP NetWeaver AS ABAP versions 700, 701, 702, 730, 731, consider restricting access to the ABAP report execution functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-27611

Affected Products

Sap Netweaver As Abap