CVE-2021-27610

Severity
9.8CRITICAL
EPSS
0.5%
top 32.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateMay 24

Description

SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDsap/netweaver_abap12 versions+11
NVDsap/netweaver_application12 versions+11

🔴Vulnerability Details

2
GHSA
GHSA-8p63-mg7m-pg66: SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about2022-05-24
CVEList
CVE-2021-27610: SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about2021-06-16
CVE-2021-27610 (CRITICAL CVSS 9.8) | SAP NetWeaver ABAP Server and ABAP | cvebase.io