cbcvebase.
CVE-2021-21488
published 2021-03-09

CVE-2021-21488: Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability.

Affected

12 ranges
VendorProductVersion rangeFixed in
sapnetweaver_knowledge_management
sapnetweaver_knowledge_management
sapnetweaver_knowledge_management
sapnetweaver_knowledge_management
sapnetweaver_knowledge_management
sapnetweaver_knowledge_management
sap_sesap_netweaver_knowledge_management< 7.017.01
sap_sesap_netweaver_knowledge_management< 7.027.02
sap_sesap_netweaver_knowledge_management< 7.307.30
sap_sesap_netweaver_knowledge_management< 7.317.31
sap_sesap_netweaver_knowledge_management< 7.407.40
sap_sesap_netweaver_knowledge_management< 7.507.50