CVE Vulnerabilities

CVE-2021-27610

Improper Authentication

Published: Jun 16, 2021 | Modified: Oct 06, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Netweaver_abap Sap 700 (including) 700 (including)
Netweaver_abap Sap 701 (including) 701 (including)
Netweaver_abap Sap 702 (including) 702 (including)
Netweaver_abap Sap 731 (including) 731 (including)
Netweaver_abap Sap 740 (including) 740 (including)
Netweaver_abap Sap 750 (including) 750 (including)
Netweaver_abap Sap 751 (including) 751 (including)
Netweaver_abap Sap 752 (including) 752 (including)
Netweaver_abap Sap 753 (including) 753 (including)
Netweaver_abap Sap 754 (including) 754 (including)
Netweaver_abap Sap 755 (including) 755 (including)
Netweaver_abap Sap 804 (including) 804 (including)
Netweaver_application_server_abap Sap 700 (including) 700 (including)
Netweaver_application_server_abap Sap 701 (including) 701 (including)
Netweaver_application_server_abap Sap 702 (including) 702 (including)
Netweaver_application_server_abap Sap 731 (including) 731 (including)
Netweaver_application_server_abap Sap 740 (including) 740 (including)
Netweaver_application_server_abap Sap 750 (including) 750 (including)
Netweaver_application_server_abap Sap 751 (including) 751 (including)
Netweaver_application_server_abap Sap 752 (including) 752 (including)
Netweaver_application_server_abap Sap 753 (including) 753 (including)
Netweaver_application_server_abap Sap 754 (including) 754 (including)
Netweaver_application_server_abap Sap 755 (including) 755 (including)
Netweaver_application_server_abap Sap 804 (including) 804 (including)

Potential Mitigations

References