Vulnerability Description
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Customer Relationship Management | 700 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3066316Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3066316Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506Vendor Advisory
FAQ
What is CVE-2021-33676?
CVE-2021-33676 is a vulnerability with a CVSS score of 7.2 (HIGH). A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the s...
How severe is CVE-2021-33676?
CVE-2021-33676 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33676?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Customer Relationship Management.