CVE-2021-27617: Input Validation
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service conditions due to consumption of a large amount of system memory, thus highly impacting system availability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27617?
CVE-2021-27617 is a vulnerability in the Integration Builder Framework of SAP Process Integration versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
What is the severity of CVE-2021-27617?
CVE-2021-27617 has a severity level of medium with a CVSS score of 4.9.
How does CVE-2021-27617 affect SAP NetWeaver Process Integration?
CVE-2021-27617 affects SAP NetWeaver Process Integration versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
What is the impact of CVE-2021-27617?
CVE-2021-27617 could lead to a denial-of-service (DoS) attack if a malicious XML document is uploaded and parsed by the application.
How can I fix CVE-2021-27617?
To fix CVE-2021-27617, SAP recommends applying the necessary software updates and patches provided in the official SAP Note 3012021.