CVE-2021-27632: Null Pointer Dereference
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27632?
The severity of CVE-2021-27632 is high with a severity value of 7.5.
How does CVE-2021-27632 affect SAP NetWeaver ABAP Server and ABAP Platform?
CVE-2021-27632 affects SAP NetWeaver ABAP Server and ABAP Platform versions KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73.
What can an unauthenticated attacker do with CVE-2021-27632?
An unauthenticated attacker without specific knowledge of the system can send a specific payload to exploit the vulnerability.
How can I fix CVE-2021-27632?
To fix CVE-2021-27632, apply the recommended patches provided by SAP and update the affected SAP NetWeaver ABAP Server and ABAP Platform versions.
Where can I find more information about CVE-2021-27632?
More information about CVE-2021-27632 can be found in the SAP support note 3020104 and the SAP Community Wiki page.