cbcvebase.
CVE-2021-27598
published 2021-04-13

CVE-2021-27598: SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.

Affected

6 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sap_sesap_netweaver_as_for_java< 7.317.31
sap_sesap_netweaver_as_for_java< 7.407.40
sap_sesap_netweaver_as_for_java< 7.507.50