CVE-2021-38163
KEVlargeUnrestricted File Upload (Path Traversal) in SAP NetWeaver
CISA: SAP NetWeaver Unrestricted File Upload Vulnerability
CVE-2021-38163 is an unrestricted file upload vulnerability in SAP NetWeaver, classified as CWE-23 (path traversal), indicating that uploaded content can likely be written outside the intended directory via crafted upload paths or filenames. It is triggered by sending a file upload request with a manipulated path or name to a vulnerable NetWeaver component. A successful attacker gains the ability to write arbitrary files to the server, which can enable persistence, tampering, or code execution depending on where the files are written and what the server executes. Organizations running SAP NetWeaver — the application platform that underlies most on-premises SAP ERP and application deployments — are affected; the affected version ranges were not specified in the source data. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-09 (ransomware use unconfirmed), EPSS assigns a 36% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.
What to do: Apply the SAP security updates referenced for CVE-2021-38163 per vendor instructions, consistent with CISA's KEV remediation requirement (typically a two-week deadline for federal agencies). Inventory for internet-facing NetWeaver application server interfaces and restrict access to them until patched. Since exploitation in the wild is confirmed, monitor affected systems for anomalous file uploads and unexpected files in web-accessible or executable locations.
| SAP NetWeaver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
- Affected
- SAP NetWeaver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sap
- Products
- netweaver
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.