Vulnerability Description
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Landscape Transformation | 2.0 |
| Sap | Landscape Transformation Replication Server | 1.0 |
| Sap | S\/4Hana | 1511 |
| Sap | Test Data Migration Server | 4.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3089831Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3089831Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
FAQ
What is CVE-2021-38176?
CVE-2021-38176 is a vulnerability with a CVSS score of 8.8 (HIGH). Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABA...
How severe is CVE-2021-38176?
CVE-2021-38176 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38176?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Landscape Transformation, Sap Landscape Transformation Replication Server, Sap S\/4Hana, Sap Test Data Migration Server.