Vulnerability Description
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | 7.11 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3078609Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3078609Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
FAQ
What is CVE-2021-37535?
CVE-2021-37535 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
How severe is CVE-2021-37535?
CVE-2021-37535 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-37535?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Java.