PT-2021-21694 · Sap · Sap Netweaver Knowledge Management Xml Forms
Yvan Genuer
·
Published
2021-09-14
·
Updated
2022-02-03
·
CVE-2021-37531
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Knowledge Management XML Forms versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50
Description
The issue allows a non-administrative authenticated attacker to craft a malicious XSL stylesheet file containing a script with OS-level commands. The attacker can copy this file into a location accessible by the system and then create a file that triggers the XSLT engine to execute the script contained within the malicious XSL file. This can result in a full compromise of the confidentiality, integrity, and availability of the system.
Recommendations
For SAP NetWeaver Knowledge Management XML Forms versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, consider disabling the XSLT engine or restricting access to it until a patch is available.
As a temporary workaround, avoid using the XSLT functionality in the affected versions to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver Knowledge Management Xml Forms