Improper Input Sanitization in SAP Products Allows Remote Code Execution
CVE-2021-38176
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 September 2021
What is CVE-2021-38176?
This vulnerability arises from insufficient input sanitization within SAP NetWeaver, enabling authenticated users with specific privileges to remotely invoke NZDT function modules. This capability allows for the execution of manipulated queries or the injection of ABAP code, potentially leading to unauthorized access to the backend database. Successful exploitation can severely undermine the confidentiality, integrity, and availability of the affected systems, highlighting the critical need for prompt remediation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Landscape Transformation < 2.0
SAP LT Replication Server < 2.0 < 2.0
SAP LT Replication Server < 3.0 < 3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved