HIGH

CVE-2021-38163

Sap Netweaver 2021-09-14 CVSS v3.1
CVSS
8.8
KEV

Description

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

Summary dbcve.org

SAP NetWeaver Visual Composer 7.0 RT (versions 7.30-7.50) contains an unrestricted file upload vulnerability allowing authenticated non-administrative users to upload malicious files that execute operating system commands with Java Server process privileges, enabling data theft, modification, or denial of service.

Mitigation

Apply SAP security notes/patches for Visual Composer to implement proper authentication, authorization, and file type validation on uploads. Restrict upload functionality to administrative users only and sanitize uploaded file content before execution.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

36.02%
Probability of exploitation in next 30 days
98.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE