CVE-2021-27631: Null Pointer Dereference
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27631?
CVE-2021-27631 has been rated as a high severity vulnerability.
How do I fix CVE-2021-27631?
To fix CVE-2021-27631, you need to apply the relevant security patch provided by SAP for the affected versions.
Which versions are affected by CVE-2021-27631?
CVE-2021-27631 affects multiple versions of SAP NetWeaver ABAP Server and ABAP Platform, specifically versions 7.22, 7.49, 7.53, 7.73, and others.
What type of vulnerability is CVE-2021-27631?
CVE-2021-27631 is categorized as an authentication bypass vulnerability.
Can CVE-2021-27631 be exploited remotely?
Yes, CVE-2021-27631 can be exploited by an unauthenticated remote attacker.