CVE-2021-40496

Severity
4.3MEDIUM
EPSS
0.4%
top 38.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 24

Description

SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDsap/netweaver_abap14 versions+13
NVDsap/netweaver_application14 versions+13

🔴Vulnerability Details

2
GHSA
GHSA-chrv-p5rc-j7c8: SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with lo2022-05-24
CVEList
CVE-2021-40496: SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with lo2021-10-12
CVE-2021-40496 (MEDIUM CVSS 4.3) | SAP Internet Communication framewor | cvebase.io