PT-2021-7873 · Sap · Abap Platform+1
Published
2021-06-16
·
Updated
2023-07-01
·
CVE-2021-27610
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver ABAP Server and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804
Description
The issue is related to improper authentication due to the inconsistent and undistinguished format of internal and external RFC user information. This could lead to malicious users obtaining illegitimate access to the system. The vulnerability is associated with deficiencies in the authentication procedure resulting from incorrect handling of RFC user information for communication between SAP systems. Exploitation of the vulnerability may allow a remote attacker to bypass security restrictions, elevate privileges, and gain unauthorized access to protected information.
Recommendations
For SAP NetWeaver ABAP Server and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, consider implementing additional security measures to ensure proper authentication and authorization, such as enhancing the handling of RFC user information to prevent improper access.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abap Platform
Sap Netweaver Abap Server