Vulnerability Description
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server For Java | 7.20 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/164592/SAP-JAVA-NetWeaver-System-ConnectionPatchThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Oct/28Mailing ListPatchThird Party Advisory
- https://launchpad.support.sap.com/#/notes/3053066Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999Vendor Advisory
- http://packetstormsecurity.com/files/164592/SAP-JAVA-NetWeaver-System-ConnectionPatchThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Oct/28Mailing ListPatchThird Party Advisory
- https://launchpad.support.sap.com/#/notes/3053066Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999Vendor Advisory
FAQ
What is CVE-2021-27635?
CVE-2021-27635 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the applic...
How severe is CVE-2021-27635?
CVE-2021-27635 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27635?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server For Java.