CVE-2021-33670
published 2021-07-14CVE-2021-33670: SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.16%
86.5th percentile
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_as_for_java | < 7.10 | 7.10 |
| sap_se | sap_netweaver_as_for_java | < 7.11 | 7.11 |
| sap_se | sap_netweaver_as_for_java | < 7.20 | 7.20 |
| sap_se | sap_netweaver_as_for_java | < 7.30 | 7.30 |
| sap_se | sap_netweaver_as_for_java | < 7.31 | 7.31 |
| sap_se | sap_netweaver_as_for_java | < 7.40 | 7.40 |
| sap_se | sap_netweaver_as_for_java | < 7.50 | 7.50 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
SAP-NetWeaver: Denial of Service in SAP NetWeaver JAVA
vendor_redhat·2022-05-04·CVSS 7.5
CVE-2021-33670 [HIGH] CWE-770 SAP-NetWeaver: Denial of Service in SAP NetWeaver JAVA
SAP-NetWeaver: Denial of Service in SAP NetWeaver JAVA
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
Package: SAP-NetWeaver (Red Hat build of Quarkus) - Not affected
Package: SAP-NetWeaver (Red Hat Fuse 7) - Not affected
Package: SAP-NetWeaver (Red Hat Integration Camel K 1) - Not affected
Package: SAP-NetWeaver (Red Hat Integration Camel Quarkus 1) - Not affected
Package: SAP-NetWeaver (Red Hat Integration Data Virtualisation Operator) - Not affected
Package: SAP-NetWeaver (Red Hat JBoss Fuse 6) - Not aff
GHSA
GHSA-cw5h-4qfv-qqr2: SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7
ghsa_unreviewed·2022-05-24
CVE-2021-33670 [HIGH] GHSA-cw5h-4qfv-qqr2: SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/166965/SAP-NetWeaver-Java-Denial-Of-Service.htmlhttp://seclists.org/fulldisclosure/2022/May/4https://launchpad.support.sap.com/#/notes/3056652https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506http://packetstormsecurity.com/files/166965/SAP-NetWeaver-Java-Denial-Of-Service.htmlhttp://seclists.org/fulldisclosure/2022/May/4https://launchpad.support.sap.com/#/notes/3056652https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506
2021-07-14
Published