PT-2021-17556 · Sap · Sap Netweaver Application Server Java

Published

2021-06-09

·

Updated

2022-07-12

·

CVE-2021-27621

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server for Java versions 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50
Description The issue allows attackers to access restricted information by entering a malicious server name in the UserAdmin application.
Recommendations For versions 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50, consider restricting access to the UserAdmin application until a fix is available. As a temporary workaround, consider validating server names to prevent malicious input. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-27621

Affected Products

Sap Netweaver Application Server Java