First published: Wed Jun 09 2021(Updated: )
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP | =kernel_7.22 | |
SAP NetWeaver AS ABAP | =kernel_7.49 | |
SAP NetWeaver AS ABAP | =kernel_7.53 | |
SAP NetWeaver AS ABAP | =kernel_7.73 | |
SAP NetWeaver AS ABAP | =kernel_7.77 | |
SAP NetWeaver AS ABAP | =kernel_7.81 | |
SAP NetWeaver AS ABAP | =kernel_7.82 | |
SAP NetWeaver AS ABAP | =kernel_7.83 | |
SAP NetWeaver AS ABAP | =kernel_8.04 | |
SAP NetWeaver AS ABAP | =krnl32nuc_7.22 | |
SAP NetWeaver AS ABAP | =krnl32nuc_7.22ext | |
SAP NetWeaver AS ABAP | =krnl64nuc_7.22 | |
SAP NetWeaver AS ABAP | =krnl64nuc_7.22ext | |
SAP NetWeaver AS ABAP | =krnl64nuc_7.49 | |
SAP NetWeaver AS ABAP | =krnl64uc_7.22 | |
SAP NetWeaver AS ABAP | =krnl64uc_7.22ext | |
SAP NetWeaver AS ABAP | =krnl64uc_7.49 | |
SAP NetWeaver AS ABAP | =krnl64uc_7.53 | |
SAP NetWeaver AS ABAP | =krnl64uc_7.73 | |
SAP NetWeaver AS ABAP | =krnl64uc_8.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27632 is high with a severity value of 7.5.
CVE-2021-27632 affects SAP NetWeaver ABAP Server and ABAP Platform versions KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73.
An unauthenticated attacker without specific knowledge of the system can send a specific payload to exploit the vulnerability.
To fix CVE-2021-27632, apply the recommended patches provided by SAP and update the affected SAP NetWeaver ABAP Server and ABAP Platform versions.
More information about CVE-2021-27632 can be found in the SAP support note 3020104 and the SAP Community Wiki page.