Vulnerability Description
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Abap | 700 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3046610Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3046610Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655Vendor Advisory
FAQ
What is CVE-2021-27611?
CVE-2021-27611 is a vulnerability with a CVSS score of 6.7 (MEDIUM). SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. T...
How severe is CVE-2021-27611?
CVE-2021-27611 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27611?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Abap.