PT-2021-7873 · Sap · Abap Platform+1

Published

2021-06-16

·

Updated

2023-07-01

·

CVE-2021-27610

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver ABAP Server and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804
Description The issue is related to improper authentication due to the inconsistent and undistinguished format of internal and external RFC user information. This could lead to malicious users obtaining illegitimate access to the system. The vulnerability is associated with deficiencies in the authentication procedure resulting from incorrect handling of RFC user information for communication between SAP systems. Exploitation of the vulnerability may allow a remote attacker to bypass security restrictions, elevate privileges, and gain unauthorized access to protected information.
Recommendations For SAP NetWeaver ABAP Server and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, consider implementing additional security measures to ensure proper authentication and authorization, such as enhancing the handling of RFC user information to prevent improper access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-04376
CVE-2021-27610

Affected Products

Abap Platform
Sap Netweaver Abap Server