ZeroHour

CVE-2021-38163

KEVlarge

Unrestricted File Upload (Path Traversal) in SAP NetWeaver

CISA: SAP NetWeaver Unrestricted File Upload Vulnerability

CVSS 3.1
8.8 high
EPSS
36%p98
Published
()
KEV added
AI analysis

CVE-2021-38163 is an unrestricted file upload vulnerability in SAP NetWeaver, classified as CWE-23 (path traversal), indicating that uploaded content can likely be written outside the intended directory via crafted upload paths or filenames. It is triggered by sending a file upload request with a manipulated path or name to a vulnerable NetWeaver component. A successful attacker gains the ability to write arbitrary files to the server, which can enable persistence, tampering, or code execution depending on where the files are written and what the server executes. Organizations running SAP NetWeaver — the application platform that underlies most on-premises SAP ERP and application deployments — are affected; the affected version ranges were not specified in the source data. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-09 (ransomware use unconfirmed), EPSS assigns a 36% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

What to do: Apply the SAP security updates referenced for CVE-2021-38163 per vendor instructions, consistent with CISA's KEV remediation requirement (typically a two-week deadline for federal agencies). Inventory for internet-facing NetWeaver application server interfaces and restrict access to them until patched. Since exploitation in the wild is confirmed, monitor affected systems for anomalous file uploads and unexpected files in web-accessible or executable locations.

Affected
SAP NetWeaver
Estimated exposure
largetens of thousands of internet-exposed SAP NetWeaver systems; full install base (largely internal) likely 100,000+ — NetWeaver is the platform for most on-premises SAP ERP estates, and historical public internet scans have shown on the order of tens of thousands of exposed SAP services, while the majority of NetWeaver deployments sit behind the firewall.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CISA Known Exploited Vulnerability
Affected
SAP NetWeaver
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sap
Products
netweaver
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.