Authorization Check Bypass in SAP NetWeaver Application Server Java
CVE-2021-37535
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 September 2021
Summary
The SAP NetWeaver Application Server Java contains a significant vulnerability in its JMS Connector Service, where the system fails to enforce necessary authorization checks for user privileges. This oversight may allow unauthorized users to gain access and perform actions that should be restricted, potentially compromising the integrity and security of the application environment. It is essential for users of the affected versions to apply recommended patches and follow best practices to mitigate the risks associated with this vulnerability.
Affected Version(s)
SAP NetWeaver Application Server Java (JMS Connector Service) < 7.11 < 7.11
SAP NetWeaver Application Server Java (JMS Connector Service) < 7.20 < 7.20
SAP NetWeaver Application Server Java (JMS Connector Service) < 7.30 < 7.30
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved