CRITICAL🇵🇱 Wersja polska

CVE-2021-33695

CVSS 9.1v3.1pub. 2021-09-15upd. 2024-11-21

Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Sap Cloud Connector

    APP
    Sap
    2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-0247CRITICAL9.8PL ✓same product

SAP Cloud Connector – wstrzyknięcie kodu (code injection) przed wersją 2.11.3

CVE-2019-0246CRITICAL9.8PL ✓same product

SAP Cloud Connector: brak uwierzytelnienia dla krytycznych funkcji

CVE-2024-25642HIGH7.4same product

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the g...

CVE-2021-33692HIGH7.5same product

SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked ...

CVE-2021-33693MEDIUM6.8same product

SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to in...