CVE-2021-27618: Malicious File Upload
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the application, which could lead to denial of service and impact the availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this SAP Process Integration vulnerability?
The vulnerability ID of this SAP Process Integration vulnerability is CVE-2021-27618.
What is the severity of CVE-2021-27618?
The severity of CVE-2021-27618 is medium with a severity value of 4.9.
What is the affected software for CVE-2021-27618?
The affected software for CVE-2021-27618 is SAP NetWeaver Process Integration versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
How can an attacker exploit CVE-2021-27618?
An attacker can exploit CVE-2021-27618 by crafting a malicious file and uploading it to the application.
Are there any references available for CVE-2021-27618?
Yes, there are references available for CVE-2021-27618. You can find them at the following links: [link1](https://launchpad.support.sap.com/#/notes/3012021) and [link2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655).