PT-2021-22911 · Sap · Sap Netweaver Application Server For Abap/Abap Platform

Published

2021-11-10

·

Updated

2022-10-06

·

CVE-2021-40504

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server for ABAP and ABAP Platform versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756
Description The issue concerns a certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform, which contains transport authorizations that exceed the expected display-only permissions.
Recommendations For versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, consider restricting access to the template role to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-40504

Affected Products

Sap Netweaver Application Server For Abap/Abap Platform