CVE-2021-21485: High severity sap netweaver as for java vulnerability
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21485?
CVE-2021-21485 is a vulnerability that allows an attacker to gain NTLM hashes of a privileged user by enticing an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java.
What is the severity of CVE-2021-21485?
CVE-2021-21485 has a severity rating of 6.5 (high).
Which software is affected by CVE-2021-21485?
SAP NetWeaver Application Server Java versions 7.10, 7.20, 7.30, 7.31, 7.40, and 7.50 are affected by CVE-2021-21485.
How can an unauthorized attacker exploit CVE-2021-21485?
An unauthorized attacker can exploit CVE-2021-21485 by enticing an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java.
Where can I find more information about CVE-2021-21485?
You can find more information about CVE-2021-21485 on the SAP Support Portal (https://launchpad.support.sap.com/#/notes/3001824) and the SAP Community Wiki (https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649).