CVE Vulnerabilities

CVE-2021-38178

Published: Oct 12, 2021 | Modified: Oct 06, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the confidentiality, integrity, and availability of the system and its data.

Affected Software

Name Vendor Start Version End Version
Netweaver_abap Sap 700 (including) 700 (including)
Netweaver_abap Sap 701 (including) 701 (including)
Netweaver_abap Sap 702 (including) 702 (including)
Netweaver_abap Sap 710 (including) 710 (including)
Netweaver_abap Sap 730 (including) 730 (including)
Netweaver_abap Sap 731 (including) 731 (including)
Netweaver_abap Sap 740 (including) 740 (including)
Netweaver_abap Sap 750 (including) 750 (including)
Netweaver_abap Sap 751 (including) 751 (including)
Netweaver_abap Sap 752 (including) 752 (including)
Netweaver_abap Sap 753 (including) 753 (including)
Netweaver_abap Sap 754 (including) 754 (including)
Netweaver_abap Sap 755 (including) 755 (including)
Netweaver_abap Sap 756 (including) 756 (including)
Netweaver_application_server_abap Sap 700 (including) 700 (including)
Netweaver_application_server_abap Sap 701 (including) 701 (including)
Netweaver_application_server_abap Sap 702 (including) 702 (including)
Netweaver_application_server_abap Sap 710 (including) 710 (including)
Netweaver_application_server_abap Sap 730 (including) 730 (including)
Netweaver_application_server_abap Sap 731 (including) 731 (including)
Netweaver_application_server_abap Sap 740 (including) 740 (including)
Netweaver_application_server_abap Sap 750 (including) 750 (including)
Netweaver_application_server_abap Sap 751 (including) 751 (including)
Netweaver_application_server_abap Sap 752 (including) 752 (including)
Netweaver_application_server_abap Sap 753 (including) 753 (including)
Netweaver_application_server_abap Sap 754 (including) 754 (including)
Netweaver_application_server_abap Sap 755 (including) 755 (including)
Netweaver_application_server_abap Sap 756 (including) 756 (including)

References