9
CVSSv2

CVE-2021-37531

Published: 14/09/2021 Updated: 02/02/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-administrative authenticated malicious user to craft a malicious XSL stylesheet file containing a script with OS-level commands, copy it into a location to be accessed by the system and then create a file which will trigger the XSLT engine to execute the script contained within the malicious XSL file. This can result in a full compromise of the confidentiality, integrity, and availability of the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver knowledge management xml forms 7.10

sap netweaver knowledge management xml forms 7.11

sap netweaver knowledge management xml forms 7.30

sap netweaver knowledge management xml forms 7.31

sap netweaver knowledge management xml forms 7.40

sap netweaver knowledge management xml forms 7.50