CVE-2021-33663Incorrect Authorization in SE SAP Netweaver AS Abap

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 59.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attacker to insert cleartext commands due to improper restriction of I/O buffering into encrypted SMTP sessions over the network which can partially impact the integrity of the application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5sap_se/sap_netweaver_as_abap< KRNL32NUC - 7.22+15
NVDsap/netweaver_application23 versions+22

🔴Vulnerability Details

2
GHSA
GHSA-276v-xm73-5p9c: SAP NetWeaver AS ABAP, versions - KRNL32NUC - 72022-05-24
CVEList
CVE-2021-33663: SAP NetWeaver AS ABAP, versions - KRNL32NUC - 72021-06-09
CVE-2021-33663 — Incorrect Authorization | cvebase