Vulnerability Description
There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755. An unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP NetWeaver Application Server ABAP and ABAP Platform.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Abap | 740 |
| Sap | Netweaver Application Server Abap | 740 |
References
- https://launchpad.support.sap.com/#/notes/3099011Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3099011Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
FAQ
What is CVE-2021-40495?
CVE-2021-40495 is a vulnerability with a CVSS score of 5.3 (MEDIUM). There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755. An unauthorized attacker can use the p...
How severe is CVE-2021-40495?
CVE-2021-40495 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40495?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Abap, Sap Netweaver Application Server Abap.