HIGH
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database
Published Sep 14, 2021
8.8
HIGHCVSS 3.1
EPSS 1.27%
Description
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.
Affected products
-
- Version < 2.0StatusaffectedConstraints-
- Version < 3.0StatusaffectedConstraints-
- Version
-
- Version < 1.0StatusaffectedConstraints-
- Version
-
- Version < 2.0StatusaffectedConstraints-
- Version
-
- Version < 1511StatusaffectedConstraints-
- Version < 1610StatusaffectedConstraints-
- Version < 1709StatusaffectedConstraints-
- Version < 1809StatusaffectedConstraints-
- Version < 1909StatusaffectedConstraints-
- Version < 2020StatusaffectedConstraints-
- Version < 2021StatusaffectedConstraints-
- Version
-
- Version < 4.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SAP SE | SAP LT Replication Server | n/a |
| ||||||||||||||||||||||||
| SAP SE | SAP LTRS for S/4HANA | n/a |
| ||||||||||||||||||||||||
| SAP SE | SAP Landscape Transformation | n/a |
| ||||||||||||||||||||||||
| SAP SE | SAP S/4hana | n/a |
| ||||||||||||||||||||||||
| SAP SE | SAP Test Data Migration Server | n/a |
|
OR
- 2.0
- 1.0
- 2.0
- 3.0
- 1511
- 1610
- 1709
- 1809
- 1909
- 2020
- 2021
- 4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-24646 Advisory
- https://launchpad.support.sap.com/#/notes/3089831 x_refsource_MISCPermissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-24646 | Advisory | |
| https://launchpad.support.sap.com/#/notes/3089831 | x_refsource_MISCPermissions Required | |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Sep 14, 2021
Updated Aug 4, 2024
Reserved Aug 7, 2021
Link CVE-2021-38176
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-24646 Assigner sap
Published Sep 14, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2021-24646