First published: Wed Jun 09 2021(Updated: )
Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS JAVA | =7.11 | |
SAP NetWeaver AS JAVA | =7.20 | |
SAP NetWeaver AS JAVA | =7.30 | |
SAP NetWeaver AS JAVA | =7.31 | |
SAP NetWeaver AS JAVA | =7.40 | |
SAP NetWeaver AS JAVA | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this information disclosure vulnerability is CVE-2021-27621.
The affected software is SAP NetWeaver Application Server for Java versions 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
The severity of CVE-2021-27621 is medium with a CVSS score of 4.9.
An attacker can exploit this vulnerability by entering a malicious server name to gain access to restricted information.
Yes, a fix for CVE-2021-27621 is available. Please refer to the SAP notes 3023299 for more information.