CVE-2021-33701
Summary
| CVE | CVE-2021-33701 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-15 19:15:00 UTC |
| Updated | 2022-04-01 18:59:00 UTC |
| Description | DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL Injection vulnerability, that highly impacts systems Confidentiality, Integrity and Availability. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Dmis | 2011_1_620 | All | All | All |
| Application | Sap | Dmis | 2011_1_640 | All | All | All |
| Application | Sap | Dmis | 2011_1_700 | All | All | All |
| Application | Sap | Dmis | 2011_1_710 | All | All | All |
| Application | Sap | Dmis | 2011_1_730 | All | All | All |
| Application | Sap | Dmis | 2011_1_731 | All | All | All |
| Application | Sap | Dmis | 2011_1_752 | All | All | All |
| Application | Sap | Dmis | 2020125 | All | All | All |
| Application | Sap | Dmis | 710 | All | All | All |
| Application | Sap | S4core | 102 | All | All | All |
| Application | Sap | S4core | 103 | All | All | All |
| Application | Sap | S4core | 104 | All | All | All |
| Application | Sap | S4core | 105 | All | All | All |
| Application | Sap | Sapscore | 125 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| Full Disclosure: SEC Consult SA-20211214-1 :: Remote ABAP Code Injection in SAP Netweaver IUUC_RECON_RC_COUNT_TABLE_BIG | FULLDISC | seclists.org | |
| SAP Netweaver IUUC_RECON_RC_COUNT_TABLE_BIG SQL Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Full Disclosure: SEC Consult SA-20211214-0 :: Remote ADBC SQL Injection in SAP Netweaver IUUC_RECON_RC_COUNT_TABLE_BIG | FULLDISC | seclists.org | |
| SAP Netweaver IUUC_RECON_RC_COUNT_TABLE_BIG ABAP Code Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| SAP Security Patch Day – August 2021 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.