CVE-2021-27635

SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_for_java:7.20:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_java:7.30:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_java:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_java:7.40:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_java:7.50:*:*:*:*:*:*:*

History

21 Nov 2024, 05:58

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/164592/SAP-JAVA-NetWeaver-System-Connections-XML-Injection.html - Patch, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/164592/SAP-JAVA-NetWeaver-System-Connections-XML-Injection.html - Patch, Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2021/Oct/28 - Mailing List, Patch, Third Party Advisory () http://seclists.org/fulldisclosure/2021/Oct/28 - Mailing List, Patch, Third Party Advisory
References () https://launchpad.support.sap.com/#/notes/3053066 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/3053066 - Permissions Required, Vendor Advisory
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 - Vendor Advisory

Information

Published : 2021-06-09 14:15

Updated : 2024-11-21 05:58


NVD link : CVE-2021-27635

Mitre link : CVE-2021-27635

CVE.ORG link : CVE-2021-27635


JSON object : View

Products Affected

sap

  • netweaver_application_server_for_java
CWE
CWE-611

Improper Restriction of XML External Entity Reference