CVE-2021-27598: Medium severity sap netweaver as for java vulnerability
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2021-27598?
Vulnerability CVE-2021-27598 is a security flaw in SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet) versions 7.31, 7.40, and 7.50.
What is the severity of vulnerability CVE-2021-27598?
The severity of vulnerability CVE-2021-27598 is medium with a CVSS score of 5.3.
How does vulnerability CVE-2021-27598 affect SAP NetWeaver AS JAVA?
Vulnerability CVE-2021-27598 allows an attacker to read some statistical data like product version, traffic, timestamp, etc. due to a missing authorization check in the Customer Usage Provisioning Servlet of SAP NetWeaver AS JAVA versions 7.31, 7.40, and 7.50.
Which versions of SAP NetWeaver AS JAVA are affected by CVE-2021-27598?
SAP NetWeaver AS JAVA versions 7.31, 7.40, and 7.50 are affected by CVE-2021-27598.
How can I mitigate CVE-2021-27598?
To mitigate CVE-2021-27598, it is recommended to apply the necessary patches provided by SAP.