SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSap Cloud Connector
APPSap< 2.11.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-33695CRITICAL9.1PL ✓same product
SAP Cloud Connector: niewystarczająca walidacja certyfikatu TLS
CVE-2019-0246CRITICAL9.8PL ✓same product
SAP Cloud Connector: brak uwierzytelnienia dla krytycznych funkcji
CVE-2024-25642HIGH7.4same product
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the g...
CVE-2021-33692HIGH7.5same product
SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked ...
CVE-2021-33694MEDIUM4.8same product
SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker ...