cbcvebase.
CVE-2021-38176
published 2021-09-14

CVE-2021-38176: Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.

Affected

24 ranges
VendorProductVersion rangeFixed in
saplandscape_transformation
saplandscape_transformation_replication_server
saplandscape_transformation_replication_server
saplandscape_transformation_replication_server
saps_4hana
saps_4hana
saps_4hana
saps_4hana
saps_4hana
saps_4hana
saps_4hana
saptest_data_migration_server
sap_sesap_landscape_transformation< 2.02.0
sap_sesap_lt_replication_server< 2.02.0
sap_sesap_lt_replication_server< 3.03.0
sap_sesap_ltrs_for_s_4hana< 1.01.0
sap_sesap_s_4hana< 15111511
sap_sesap_s_4hana< 16101610
sap_sesap_s_4hana< 17091709
sap_sesap_s_4hana< 18091809
sap_sesap_s_4hana< 19091909
sap_sesap_s_4hana< 20202020
sap_sesap_s_4hana< 20212021
sap_sesap_test_data_migration_server< 4.04.0