CVE-2021-27621: Medium severity sap netweaver java application server vulnerability
Published Jun 9, 2021
·Updated
Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name.
Affected Software
6 affected components
SAP NetWeaver Application Server for Java=7.11
SAP NetWeaver Application Server for Java=7.20
SAP NetWeaver Application Server for Java=7.30
SAP NetWeaver Application Server for Java=7.31
SAP NetWeaver Application Server for Java=7.40
SAP NetWeaver Application Server for Java=7.50
Event History
Jun 9, 2021
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this information disclosure vulnerability?
The vulnerability ID for this information disclosure vulnerability is CVE-2021-27621.
2
What is the affected software?
The affected software is SAP NetWeaver Application Server for Java versions 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
3
What is the severity of CVE-2021-27621?
The severity of CVE-2021-27621 is medium with a CVSS score of 4.9.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by entering a malicious server name to gain access to restricted information.
5
Is there a fix available for CVE-2021-27621?
Yes, a fix for CVE-2021-27621 is available. Please refer to the SAP notes 3023299 for more information.