Vulnerability Description
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Abap Platform | 701 |
| Sap | Netweaver Application Server Abap | 701 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3119365Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3119365Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021Vendor Advisory
FAQ
What is CVE-2021-44231?
CVE-2021-44231 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
How severe is CVE-2021-44231?
CVE-2021-44231 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-44231?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Abap Platform, Sap Netweaver Application Server Abap.