CVE-2021-21481
Summary
| CVE | CVE-2021-21481 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-09 15:15:00 UTC |
| Updated | 2021-03-16 17:34:00 UTC |
| Description | The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of system confidentiality, integrity, and availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| launchpad.support.sap.com |
MISC |
launchpad.support.sap.com |
Permissions Required, Vendor Advisory |
| SAP Security Patch Day – March 2021 - Product Security Response at SAP - Community Wiki |
MISC |
wiki.scn.sap.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 87463 SAP NetWeaver AS Java Missing Authorization Check Vulnerability