6.3
CVSSv3

CVE-2021-21473

Published: 09/06/2021 Updated: 05/10/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 6.3 | Impact Score: 3.4 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver application server abap 702

sap netweaver application server abap 750

sap netweaver application server abap 752

sap netweaver application server abap 753

sap netweaver application server abap 754

sap netweaver application server abap 755

sap netweaver application server abap 700

sap netweaver application server abap 710

sap netweaver application server abap 730

sap netweaver application server abap 731

sap netweaver application server abap 711

sap netweaver application server abap 740

sap netweaver application server abap 751

Exploits

The SAP application server ABAP and ABAP Platform are susceptible to code injection, SQL injection, and missing authorization vulnerabilities Multiple SAP products are affected ...