CVE-2021-27611: Code Injection
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27611?
CVE-2021-27611 has a high severity rating due to the potential for code injection and unauthorized data access.
How do I fix CVE-2021-27611?
To mitigate CVE-2021-27611, upgrade your SAP NetWeaver AS ABAP to the latest supported version as recommended by SAP.
Who is affected by CVE-2021-27611?
CVE-2021-27611 affects users of SAP NetWeaver AS ABAP versions 700, 701, 702, 730, and 731.
What types of attacks can CVE-2021-27611 enable?
CVE-2021-27611 can enable an attacker to execute arbitrary ABAP code, potentially leading to data manipulation or denial of service.
What actions should be taken to secure against CVE-2021-27611?
To secure against CVE-2021-27611, ensure proper access controls are in place and regularly apply updates provided by SAP.