CVE Vulnerabilities

CVE-2021-33670

Published: Jul 14, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Netweaver_application_server_javaSap7.10 (including)7.10 (including)
Netweaver_application_server_javaSap7.11 (including)7.11 (including)
Netweaver_application_server_javaSap7.20 (including)7.20 (including)
Netweaver_application_server_javaSap7.30 (including)7.30 (including)
Netweaver_application_server_javaSap7.31 (including)7.31 (including)
Netweaver_application_server_javaSap7.40 (including)7.40 (including)
Netweaver_application_server_javaSap7.50 (including)7.50 (including)

References