MEDIUM🇵🇱 Wersja polska

CVE-2021-33689

CVSS 4.3v3.1pub. 2021-07-14upd. 2024-11-21

When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Sap Netweaver Application Server Java

    APP
    Sap
    7.50
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-6287CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard

CVE-2010-5326CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — RCE przez Invoker Servlet bez uwierzytelnienia

CVE-2016-2386CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w serwerze UDDI SAP NetWeaver J2EE Engine 7.40

CVE-2024-22127CRITICAL9.1PL ✓same product

SAP NetWeaver AS Java – command injection przez upload pliku w Log Viewer

CVE-2023-40309CRITICAL9.8PL ✓same product

SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation