CVE-2021-33687
Published on: 07/14/2021 12:00:00 AM UTC
Last Modified on: 05/03/2022 04:04:00 PM UTC
Certain versions of Netweaver Application Server Java from Sap contain the following vulnerability:
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
- CVE-2021-33687 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 4.9 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Full Disclosure: Onapsis Security Advisory 2021-0020: SAP Enterprise Portal - Exposed sensitive data in html body | seclists.org text/html |
![]() |
SAP Enterprise Portal Sensitive Data Disclosure ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
No Description Provided | launchpad.support.sap.com text/html |
![]() |
SAP Security Patch Day – July 2021 - Product Security Response at SAP - Community Wiki | wiki.scn.sap.com text/html |
![]() |
Related QID Numbers
- 87512 SAP NetWeaver AS for Java Information Disclosure Vulnerability
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Sap | Netweaver Application Server Java | 7.10 | All | All | All |
Application | Sap | Netweaver Application Server Java | 7.20 | All | All | All |
Application | Sap | Netweaver Application Server Java | 7.30 | All | All | All |
Application | Sap | Netweaver Application Server Java | 7.31 | All | All | All |
Application | Sap | Netweaver Application Server Java | 7.40 | All | All | All |
Application | Sap | Netweaver Application Server Java | 7.50 | All | All | All |
- cpe:2.3:a:sap:netweaver_application_server_java:7.10:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:netweaver_application_server_java:7.20:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-33687 : #SAP NetWeaver AS JAVA Enterprise Portal , versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals… twitter.com/i/web/status/1… | 2021-07-14 11:47:17 |
![]() |
CVE-2021-33687 | 2021-07-14 12:41:23 |