Show filters
58 Total Results
Displaying 11-20 of 58
Sort by:
Attacker Value
Unknown
CVE-2021-33670
Disclosure Date: July 14, 2021 (last updated November 28, 2024)
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
0
Attacker Value
Unknown
CVE-2021-33671
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. The impact of missing authorization could result to abuse of functionality restricted to a particular user group, and could allow unauthorized users to read, modify or delete restricted data.
0
Attacker Value
Unknown
CVE-2021-33687
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
0
Attacker Value
Unknown
CVE-2021-27617
Disclosure Date: May 11, 2021 (last updated February 22, 2025)
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service conditions due to consumption of a large amount of system memory, thus highly impacting system availability.
0
Attacker Value
Unknown
CVE-2021-27618
Disclosure Date: May 11, 2021 (last updated February 22, 2025)
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the application, which could lead to denial of service and impact the availability of the application.
0
Attacker Value
Unknown
CVE-2021-27599
Disclosure Date: April 14, 2021 (last updated November 28, 2024)
SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2021-27604
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP recommends to refer this note.
0
Attacker Value
Unknown
CVE-2021-21482
Disclosure Date: April 13, 2021 (last updated November 28, 2024)
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information disclosure vulnerability thereby affecting the confidentiality and integrity of the application. This happens when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.
0
Attacker Value
Unknown
CVE-2021-27601
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have control over kind or degree.
0
Attacker Value
Unknown
CVE-2021-21485
Disclosure Date: April 13, 2021 (last updated November 28, 2024)
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.
0