CVE-2021-33695: Critical severity sap cloud connector vulnerability
Published Sep 15, 2021
·Updated
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.
Affected Software
1 affected component
SAP Cloud Connector=2.0
Remediation
Event History
Sep 15, 2021
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-33695?
CVE-2021-33695 has a medium severity level due to insufficient validation of the certificate during backend communication.
2
How do I fix CVE-2021-33695?
To fix CVE-2021-33695, ensure that proper certificate validation mechanisms are implemented in your SAP Cloud Connector configuration.
3
What versions of SAP Cloud Connector are affected by CVE-2021-33695?
CVE-2021-33695 affects SAP Cloud Connector version 2.0.
4
Can CVE-2021-33695 lead to unauthorized access?
Yes, CVE-2021-33695 can potentially allow unauthorized access if the certificate validation is not enforced.
5
Is there a workaround for CVE-2021-33695?
Currently, the recommended course of action for CVE-2021-33695 is to apply the necessary updates that enforce proper certificate validation.