HIGH · 8.8

CVE-2021-38176

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABA...

Vulnerability Description

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SapLandscape Transformation2.0
SapLandscape Transformation Replication Server1.0
SapS\/4Hana1511
SapTest Data Migration Server4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-38176?

CVE-2021-38176 is a vulnerability with a CVSS score of 8.8 (HIGH). Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABA...

How severe is CVE-2021-38176?

CVE-2021-38176 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-38176?

Check the references section above for vendor advisories and patch information. Affected products include: Sap Landscape Transformation, Sap Landscape Transformation Replication Server, Sap S\/4Hana, Sap Test Data Migration Server.