CVE Vulnerabilities

CVE-2021-27631

NULL Pointer Dereference

Published: Jun 09, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Netweaver_as_abapSapkernel_7.22 (including)kernel_7.22 (including)
Netweaver_as_abapSapkernel_7.49 (including)kernel_7.49 (including)
Netweaver_as_abapSapkernel_7.53 (including)kernel_7.53 (including)
Netweaver_as_abapSapkernel_7.73 (including)kernel_7.73 (including)
Netweaver_as_abapSapkernel_7.77 (including)kernel_7.77 (including)
Netweaver_as_abapSapkernel_7.81 (including)kernel_7.81 (including)
Netweaver_as_abapSapkernel_7.82 (including)kernel_7.82 (including)
Netweaver_as_abapSapkernel_7.83 (including)kernel_7.83 (including)
Netweaver_as_abapSapkernel_8.04 (including)kernel_8.04 (including)
Netweaver_as_abapSapkrnl32nuc_7.22 (including)krnl32nuc_7.22 (including)
Netweaver_as_abapSapkrnl32nuc_7.22ext (including)krnl32nuc_7.22ext (including)
Netweaver_as_abapSapkrnl64nuc_7.22 (including)krnl64nuc_7.22 (including)
Netweaver_as_abapSapkrnl64nuc_7.22ext (including)krnl64nuc_7.22ext (including)
Netweaver_as_abapSapkrnl64nuc_7.49 (including)krnl64nuc_7.49 (including)
Netweaver_as_abapSapkrnl64uc_7.22 (including)krnl64uc_7.22 (including)
Netweaver_as_abapSapkrnl64uc_7.22ext (including)krnl64uc_7.22ext (including)
Netweaver_as_abapSapkrnl64uc_7.49 (including)krnl64uc_7.49 (including)
Netweaver_as_abapSapkrnl64uc_7.53 (including)krnl64uc_7.53 (including)
Netweaver_as_abapSapkrnl64uc_7.73 (including)krnl64uc_7.73 (including)
Netweaver_as_abapSapkrnl64uc_8.04 (including)krnl64uc_8.04 (including)

Potential Mitigations

References