CVE Vulnerabilities

CVE-2021-27631

NULL Pointer Dereference

Published: Jun 09, 2021 | Modified: Oct 31, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Netweaver_as_abap Sap kernel_7.22 (including) kernel_7.22 (including)
Netweaver_as_abap Sap kernel_7.49 (including) kernel_7.49 (including)
Netweaver_as_abap Sap kernel_7.53 (including) kernel_7.53 (including)
Netweaver_as_abap Sap kernel_7.73 (including) kernel_7.73 (including)
Netweaver_as_abap Sap kernel_7.77 (including) kernel_7.77 (including)
Netweaver_as_abap Sap kernel_7.81 (including) kernel_7.81 (including)
Netweaver_as_abap Sap kernel_7.82 (including) kernel_7.82 (including)
Netweaver_as_abap Sap kernel_7.83 (including) kernel_7.83 (including)
Netweaver_as_abap Sap kernel_8.04 (including) kernel_8.04 (including)
Netweaver_as_abap Sap krnl32nuc_7.22 (including) krnl32nuc_7.22 (including)
Netweaver_as_abap Sap krnl32nuc_7.22ext (including) krnl32nuc_7.22ext (including)
Netweaver_as_abap Sap krnl64nuc_7.22 (including) krnl64nuc_7.22 (including)
Netweaver_as_abap Sap krnl64nuc_7.22ext (including) krnl64nuc_7.22ext (including)
Netweaver_as_abap Sap krnl64nuc_7.49 (including) krnl64nuc_7.49 (including)
Netweaver_as_abap Sap krnl64uc_7.22 (including) krnl64uc_7.22 (including)
Netweaver_as_abap Sap krnl64uc_7.22ext (including) krnl64uc_7.22ext (including)
Netweaver_as_abap Sap krnl64uc_7.49 (including) krnl64uc_7.49 (including)
Netweaver_as_abap Sap krnl64uc_7.53 (including) krnl64uc_7.53 (including)
Netweaver_as_abap Sap krnl64uc_7.73 (including) krnl64uc_7.73 (including)
Netweaver_as_abap Sap krnl64uc_8.04 (including) krnl64uc_8.04 (including)

Potential Mitigations

References