ZeroHour

CVE-2021-21481

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
Description

The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of system confidentiality, integrity, and availability.

Vendors
sap
Products
netweaver
Weakness
CWE-863
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news