CVE Vulnerabilities

CVE-2021-42067

Published: Jan 14, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.

Affected Software

NameVendorStart VersionEnd Version
Netweaver_abapSap701 (including)701 (including)
Netweaver_abapSap702 (including)702 (including)
Netweaver_abapSap711 (including)711 (including)
Netweaver_abapSap730 (including)730 (including)
Netweaver_abapSap731 (including)731 (including)
Netweaver_abapSap740 (including)740 (including)
Netweaver_abapSap750 (including)750 (including)
Netweaver_abapSap751 (including)751 (including)
Netweaver_abapSap752 (including)752 (including)
Netweaver_abapSap753 (including)753 (including)
Netweaver_abapSap754 (including)754 (including)
Netweaver_abapSap755 (including)755 (including)
Netweaver_abapSap756 (including)756 (including)
Netweaver_abapSap786 (including)786 (including)
Netweaver_application_server_abapSap701 (including)701 (including)
Netweaver_application_server_abapSap702 (including)702 (including)
Netweaver_application_server_abapSap711 (including)711 (including)
Netweaver_application_server_abapSap730 (including)730 (including)
Netweaver_application_server_abapSap731 (including)731 (including)
Netweaver_application_server_abapSap740 (including)740 (including)
Netweaver_application_server_abapSap750 (including)750 (including)
Netweaver_application_server_abapSap751 (including)751 (including)
Netweaver_application_server_abapSap752 (including)752 (including)
Netweaver_application_server_abapSap753 (including)753 (including)
Netweaver_application_server_abapSap754 (including)754 (including)
Netweaver_application_server_abapSap755 (including)755 (including)
Netweaver_application_server_abapSap756 (including)756 (including)
Netweaver_application_server_abapSap786 (including)786 (including)

References