Aller au contenu

Fiche vulnérabilité

CVE-2021-38163 : faille exploitée sap netweaver (CVSS 8.8)

Description

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
14 sept. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • sap netweaver

Correctif et mesures

Apply updates per vendor instructions.

Références

Rechercher une autre vulnérabilité dans la base CVE