Insecure Deserialization Vulnerability in SAP Knowledge Management
CVE-2021-21488

6.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 March 2021

Summary

SAP Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, and 7.50 are vulnerable to insecure deserialization. This vulnerability allows a remote attacker with basic privileges to manipulate user-controlled data without adequate verification. An exploit can lead to the execution of arbitrary code in the context of the application, potentially impacting the availability of services. Organizations using affected versions are recommended to apply available patches and implement security best practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

SAP NetWeaver Knowledge Management < 7.01 < 7.01

SAP NetWeaver Knowledge Management < 7.02 < 7.02

SAP NetWeaver Knowledge Management < 7.30 < 7.30

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.