CVE Vulnerabilities

CVE-2021-38178

Published: Oct 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the confidentiality, integrity, and availability of the system and its data.

Affected Software

NameVendorStart VersionEnd Version
Netweaver_abapSap700 (including)700 (including)
Netweaver_abapSap701 (including)701 (including)
Netweaver_abapSap702 (including)702 (including)
Netweaver_abapSap710 (including)710 (including)
Netweaver_abapSap730 (including)730 (including)
Netweaver_abapSap731 (including)731 (including)
Netweaver_abapSap740 (including)740 (including)
Netweaver_abapSap750 (including)750 (including)
Netweaver_abapSap751 (including)751 (including)
Netweaver_abapSap752 (including)752 (including)
Netweaver_abapSap753 (including)753 (including)
Netweaver_abapSap754 (including)754 (including)
Netweaver_abapSap755 (including)755 (including)
Netweaver_abapSap756 (including)756 (including)
Netweaver_application_server_abapSap700 (including)700 (including)
Netweaver_application_server_abapSap701 (including)701 (including)
Netweaver_application_server_abapSap702 (including)702 (including)
Netweaver_application_server_abapSap710 (including)710 (including)
Netweaver_application_server_abapSap730 (including)730 (including)
Netweaver_application_server_abapSap731 (including)731 (including)
Netweaver_application_server_abapSap740 (including)740 (including)
Netweaver_application_server_abapSap750 (including)750 (including)
Netweaver_application_server_abapSap751 (including)751 (including)
Netweaver_application_server_abapSap752 (including)752 (including)
Netweaver_application_server_abapSap753 (including)753 (including)
Netweaver_application_server_abapSap754 (including)754 (including)
Netweaver_application_server_abapSap755 (including)755 (including)
Netweaver_application_server_abapSap756 (including)756 (including)

References