CVE-2021-38163
Description
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
Summary dbcve.org
SAP NetWeaver Visual Composer 7.0 RT (versions 7.30-7.50) contains an unrestricted file upload vulnerability allowing authenticated non-administrative users to upload malicious files that execute operating system commands with Java Server process privileges, enabling data theft, modification, or denial of service.
Mitigation
Apply SAP security notes/patches for Visual Composer to implement proper authentication, authorization, and file type validation on uploads. Restrict upload functionality to administrative users only and sanitize uploaded file content before execution.