CVE-2021-27607: Null Pointer Dereference
SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method ThSncIn() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27607?
CVE-2021-27607 is considered a critical vulnerability due to the potential for unauthenticated remote code execution.
How do I fix CVE-2021-27607?
To mitigate CVE-2021-27607, SAP recommends updating to the latest supported versions of affected products and applying the relevant security patches.
What are the affected versions in CVE-2021-27607?
CVE-2021-27607 affects multiple versions of SAP NetWeaver ABAP Server including versions 7.22, 7.49, 7.53, 7.73, 7.77, 7.81, 7.82, 7.83, and 8.04.
Can CVE-2021-27607 be exploited remotely?
Yes, CVE-2021-27607 can be exploited by an unauthenticated attacker remotely, making it particularly dangerous.
What impact does CVE-2021-27607 have on SAP NetWeaver systems?
Exploitation of CVE-2021-27607 may allow attackers to execute arbitrary code on vulnerable SAP NetWeaver systems.