CVE-2021-33689Insufficient Logging in SE SAP Netweaver AS Java

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 54.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-vwfv-c6hj-hp8f: When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 72022-05-24
CVEList
CVE-2021-33689: When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 72021-07-14
CVE-2021-33689 — Insufficient Logging | cvebase