Vulnerability Description
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Abap | 700 |
| Sap | Netweaver Application Server Abap | 700 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3087254Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3087254Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
FAQ
What is CVE-2021-40496?
CVE-2021-40496 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication f...
How severe is CVE-2021-40496?
CVE-2021-40496 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40496?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Abap, Sap Netweaver Application Server Abap.