Server-Side Request Forgery in SAP NetWeaver Portal's Iviews Editor
CVE-2021-33705
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 15 September 2021
What is CVE-2021-33705?
The SAP NetWeaver Portal Iviews Editor component is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This allows unauthenticated attackers to craft malicious URLs that, when accessed by a user, can initiate requests to any internal or external server. This exploitation could lead to unauthorized access or modification of data linked to the Portal, although it does not compromise the system's availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver Enterprise Portal < 7.10 < 7.10
SAP NetWeaver Enterprise Portal < 7.11 < 7.11
SAP NetWeaver Enterprise Portal < 7.20 < 7.20
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved