PT-2021-21976 · Sap · Kernel+2

Martin Doyhenard

+1

·

Published

2021-09-14

·

Updated

2023-07-10

·

CVE-2021-38162

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions: SAP Web Dispatcher versions 7.49, 7.53, 7.77, 7.81 KRNL64NUC versions 7.22, 7.22EXT, 7.49 KRNL64UC versions 7.22, 7.22EXT, 7.49, 7.53 KERNEL versions 7.22, 7.49, 7.53, 7.77, 7.81, 7.83
Description: The issue allows an unauthenticated attacker to submit a malicious crafted request over a network to a front-end server, which may result in a back-end server confusing the boundaries of malicious and legitimate messages. This can lead to the back-end server executing a malicious payload, allowing the attacker to read or modify any information on the server or consume server resources, making it temporarily unavailable.
Recommendations: For SAP Web Dispatcher versions 7.49, 7.53, 7.77, 7.81, update to a version that includes the fix for this issue. For KRNL64NUC versions 7.22, 7.22EXT, 7.49, update to a version that includes the fix for this issue. For KRNL64UC versions 7.22, 7.22EXT, 7.49, 7.53, update to a version that includes the fix for this issue. For KERNEL versions 7.22, 7.49, 7.53, 7.77, 7.81, 7.83, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the front-end server to minimize the risk of exploitation.

Exploit

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2021-38162

Affected Products

Kernel
Krnl64Uc
Sap Web Dispatcher