First published: Wed Jun 09 2021(Updated: )
SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method ThSncIn() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server for ABAP | =kernel_7.22 | |
SAP NetWeaver Application Server for ABAP | =kernel_7.49 | |
SAP NetWeaver Application Server for ABAP | =kernel_7.53 | |
SAP NetWeaver Application Server for ABAP | =kernel_7.73 | |
SAP NetWeaver Application Server for ABAP | =kernel_7.77 | |
SAP NetWeaver Application Server for ABAP | =kernel_7.81 | |
SAP NetWeaver Application Server for ABAP | =kernel_7.82 | |
SAP NetWeaver Application Server for ABAP | =kernel_7.83 | |
SAP NetWeaver Application Server for ABAP | =kernel_8.04 | |
SAP NetWeaver Application Server for ABAP | =krnl32nuc_7.22 | |
SAP NetWeaver Application Server for ABAP | =krnl32nuc_7.22ext | |
SAP NetWeaver Application Server for ABAP | =krnl32uc_7.22 | |
SAP NetWeaver Application Server for ABAP | =krnl32uc_7.22ext | |
SAP NetWeaver Application Server for ABAP | =krnl64nuc_7.22 | |
SAP NetWeaver Application Server for ABAP | =krnl64nuc_7.22ext | |
SAP NetWeaver Application Server for ABAP | =krnl64nuc_7.49 | |
SAP NetWeaver Application Server for ABAP | =krnl64uc_7.22 | |
SAP NetWeaver Application Server for ABAP | =krnl64uc_7.22ext | |
SAP NetWeaver Application Server for ABAP | =krnl64uc_7.49 | |
SAP NetWeaver Application Server for ABAP | =krnl64uc_7.53 | |
SAP NetWeaver Application Server for ABAP | =krnl64uc_7.73 | |
SAP NetWeaver Application Server for ABAP | =krnl64uc_8.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27607 is considered a critical vulnerability due to the potential for unauthenticated remote code execution.
To mitigate CVE-2021-27607, SAP recommends updating to the latest supported versions of affected products and applying the relevant security patches.
CVE-2021-27607 affects multiple versions of SAP NetWeaver ABAP Server including versions 7.22, 7.49, 7.53, 7.73, 7.77, 7.81, 7.82, 7.83, and 8.04.
Yes, CVE-2021-27607 can be exploited by an unauthenticated attacker remotely, making it particularly dangerous.
Exploitation of CVE-2021-27607 may allow attackers to execute arbitrary code on vulnerable SAP NetWeaver systems.