Aller au contenu

Fiche vulnérabilité

CVE-2021-27629 : faille élevée SAP SE SAP NetWeaver ABAP Server and… (CVSS 7.5)

Description

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EncPSetUnsupported() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
9 juin 2021
Dernière mise à jour
3 août 2024

Produits concernés

  • SAP SE SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server)

Références

Rechercher une autre vulnérabilité dans la base CVE