PT-2021-22901 · Sap · Sap Netweaver Application Server For Abap/Abap Platform

Published

2021-10-12

·

Updated

2022-10-06

·

CVE-2021-40495

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server for ABAP and ABAP Platform versions 740, 750, 751, 752, 753, 754, 755
Description The issue involves multiple Denial-of-Service vulnerabilities. An unauthorized attacker can utilize the public SICF service "/sap/public/bc/abap" to reduce the performance of the SAP NetWeaver Application Server ABAP and ABAP Platform.
Recommendations For versions 740, 750, 751, 752, 753, 754, 755, consider restricting access to the public SICF service "/sap/public/bc/abap" to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2021-40495

Affected Products

Sap Netweaver Application Server For Abap/Abap Platform