CVE-2021-21492: Medium severity sap netweaver as for java vulnerability
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21492?
The severity of CVE-2021-21492 is medium.
What is the vulnerability in SAP NetWeaver Application Server Java(HTTP Service) versions 7.10 7.11 7.20 7.30 7.31 7.40 7.50?
The vulnerability in these versions is a content spoofing vulnerability caused by insufficient validation of logon group in URLs when directory listing is enabled.
How does the content spoofing vulnerability in CVE-2021-21492 impact SAP NetWeaver Application Server Java(HTTP Service)?
The content spoofing vulnerability in CVE-2021-21492 allows an attacker to manipulate the content displayed on the affected server.
How can I fix the content spoofing vulnerability in SAP NetWeaver Application Server Java(HTTP Service) versions 7.10 7.11 7.20 7.30 7.31 7.40 7.50?
To fix the vulnerability, update SAP NetWeaver Application Server Java to a patched version provided by SAP.
Where can I find more information about CVE-2021-21492?
You can find more information about CVE-2021-21492 in the SAP support portal and the SAP community wiki.