Information Disclosure Vulnerability in SAP NetWeaver ABAP Server
CVE-2021-27599

6.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 April 2021

Summary

The vulnerability in SAP NetWeaver ABAP Server and ABAP Platform's Process Integration - Integration Builder Framework allows unauthorized access to restricted information under certain circumstances. This misconfiguration can potentially expose sensitive data, leading to security concerns for organizations using affected versions, including 7.10, 7.30, 7.31, 7.40, and 7.50. Proper security measures and updates are essential to mitigate the risks associated with this exposure.

Affected Version(s)

SAP Process Integration (Integration Builder Framework) < 7.10 < 7.10

SAP Process Integration (Integration Builder Framework) < 7.30 < 7.30

SAP Process Integration (Integration Builder Framework) < 7.31 < 7.31

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.