Authorization Check Bypass in SAP NetWeaver Application Server Java
CVE-2021-37535

10CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 September 2021

Summary

The SAP NetWeaver Application Server Java contains a significant vulnerability in its JMS Connector Service, where the system fails to enforce necessary authorization checks for user privileges. This oversight may allow unauthorized users to gain access and perform actions that should be restricted, potentially compromising the integrity and security of the application environment. It is essential for users of the affected versions to apply recommended patches and follow best practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

SAP NetWeaver Application Server Java (JMS Connector Service) < 7.11 < 7.11

SAP NetWeaver Application Server Java (JMS Connector Service) < 7.20 < 7.20

SAP NetWeaver Application Server Java (JMS Connector Service) < 7.30 < 7.30

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.