Security Flaw in SAP Software Provisioning Manager by SAP
CVE-2021-21472
6.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 9 February 2021
Summary
The SAP Software Provisioning Manager 1.0 lacks an option to set a password during installation, which poses a significant security risk. This deficiency allows authenticated attackers to exploit the system through various detrimental methods, such as Directory Traversal, Password Brute Force Attacks, SMB Relay Attacks, and Security Downgrade. Organizations using this software should prioritize remediation steps to protect sensitive data and maintain system integrity.
Affected Version(s)
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) < 1.0
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved