CVE-2021-44235OS Command Injection in SE SAP Netweaver AS Abap

Severity
6.7MEDIUMNVD
EPSS
0.1%
top 69.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateDec 15

Description

Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system, that could highly impact the Confidentiality, Integrity and Availability of the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5sap_se/sap_netweaver_as_abap< 700+14
NVDsap/netweaver_application15 versions+14

🔴Vulnerability Details

2
GHSA
GHSA-pchw-x6hv-9cvj: Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an2021-12-15
CVEList
CVE-2021-44235: Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an2021-12-14
CVE-2021-44235 — OS Command Injection | cvebase