Information Disclosure Vulnerability in SAP NetWeaver ABAP Server
CVE-2021-27599
6.5MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 April 2021
Summary
The vulnerability in SAP NetWeaver ABAP Server and ABAP Platform's Process Integration - Integration Builder Framework allows unauthorized access to restricted information under certain circumstances. This misconfiguration can potentially expose sensitive data, leading to security concerns for organizations using affected versions, including 7.10, 7.30, 7.31, 7.40, and 7.50. Proper security measures and updates are essential to mitigate the risks associated with this exposure.
Affected Version(s)
SAP Process Integration (Integration Builder Framework) < 7.10 < 7.10
SAP Process Integration (Integration Builder Framework) < 7.30 < 7.30
SAP Process Integration (Integration Builder Framework) < 7.31 < 7.31
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved