HTTP Request Smuggling Vulnerability in SAP Web Dispatcher
CVE-2021-38162

8.9HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 September 2021

Summary

The vulnerability in SAP Web Dispatcher allows an unauthorized attacker to send a specially crafted request to a front-end server. This results in confusion between malicious and legitimate requests, potentially leading the back-end server to execute a malicious payload. The implications can include unauthorized reading or modification of sensitive data and resource exhaustion, making the server temporarily unavailable.

Affected Version(s)

SAP Web Dispatcher WEBDISP - 7.49

SAP Web Dispatcher 7.53

SAP Web Dispatcher 7.77

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.