CVE Database
/

CVE-2021-38176

Back to search

CVE-2021-38176

Published: Sep 14, 2021

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

9.9

CRITICAL

Description

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.

VendorProductVersions

SAP SE

SAP S/4HANA

affected
< 1511
affected
< 1610
affected
< 1709
affected
< 1809
affected
< 1909

+2 more versions

SAP SE

SAP LT Replication Server

affected
< 2.0
affected
< 3.0

SAP SE

SAP LTRS for S/4HANA

affected
< 1.0

SAP SE

SAP Test Data Migration Server

affected
< 4.0

SAP SE

SAP Landscape Transformation

affected
< 2.0

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now