← Back

CVE-2021-33684

nvd nist
Published: Jul 14, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.77, 7.81, 7.84, allows an attacker to send overlong content in the RFC request type thereby crashing the corresponding work process because of memory corruption vulnerability. The work process will attempt to restart itself after the crash and hence the impact on the availability is low.

Affected (26)

2 products
Netweaver Abap
Netweaver Application Server Abap
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 7.21
Version 7.21ext
Version 7.22
Version 7.22ext
Version 7.49
Version 7.53
Version 7.77
Version 7.81
Version kernel_8.04
Version krnl32nuc_7.21
Version krnl32uc_7.21
Version krnl64nuc_7.21
Version krnl64uc_8.04
Sap
Version 7.21
Version 7.21ext
Version 7.22
Version 7.22ext
Version 7.49
Version 7.53
Version 7.77
Version 7.81
Version kernel_8.04
Version krnl32nuc_7.21
Version krnl32uc_7.21
Version krnl64nuc_7.21
Version krnl64uc_8.04

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.