Vulnerability Description
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system, that could highly impact the Confidentiality, Integrity and Availability of the system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Abap | 700 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3123196Permissions Required
- https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3123196Permissions Required
- https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021Vendor Advisory
FAQ
What is CVE-2021-44235?
CVE-2021-44235 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct acce...
How severe is CVE-2021-44235?
CVE-2021-44235 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44235?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Abap.