← Back

CVE-2021-38176

nvd nist
Published: Sep 14, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.

Affected (12)

4 products
Landscape Transformation
S/4hana
Test Data Migration Server
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0
Sap
Version 1.0
Version 2.0
Version 3.0
Sap
Version 1511
Version 1610
Version 1709
Version 1809
Version 1909
Version 2020
Version 2021
Version 4.0

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.