CVE-2021-33676: High severity sap customer relationship management vulnerability
Published Jul 14, 2021
·Updated
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
Affected Software
6 affected components
SAP Customer Relationship Management=700
SAP Customer Relationship Management=701
SAP Customer Relationship Management=702
SAP Customer Relationship Management=712
SAP Customer Relationship Management=713
SAP Customer Relationship Management=714
Event History
Jul 14, 2021
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this SAP CRM vulnerability?
The vulnerability ID is CVE-2021-33676.
2
What is the affected software for CVE-2021-33676?
The affected software is SAP Customer Relationship Management versions 700, 701, 702, 712, 713, and 714.
3
What is the severity of CVE-2021-33676?
The severity of CVE-2021-33676 is high with a CVSS score of 7.2.
4
How can an attacker exploit CVE-2021-33676?
An attacker with high privileges can leverage the missing authority check in SAP CRM to compromise confidentiality, integrity, or availability of the system.
5
How can I fix CVE-2021-33676?
To fix CVE-2021-33676, apply the relevant SAP Security Notes from the provided references.