CVE-2021-27630: Null Pointer Dereference
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27630?
CVE-2021-27630 is rated as significant due to its potential for exploitation by unauthenticated attackers.
How do I fix CVE-2021-27630?
To remediate CVE-2021-27630, ensure that your SAP NetWeaver ABAP Server is updated to the latest version or apply the recommended patches from SAP.
What affects CVE-2021-27630?
CVE-2021-27630 affects multiple versions of SAP NetWeaver ABAP Server, including kernel versions 7.22, 7.49, 7.53, 7.73, and 8.04.
What is the impact of CVE-2021-27630?
The impact of CVE-2021-27630 can lead to unauthorized access and control over the affected SAP systems.
Is CVE-2021-27630 actively being exploited?
There have been indications that CVE-2021-27630 may be actively exploited in the wild, emphasizing the need for prompt action.