CVE-2021-37535: Critical severity SAP NetWeaver Application Server Java vulnerability
Published Sep 14, 2021
·Updated
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
Affected Software
6 affected components
SAP NetWeaver Application Server Java=7.11
SAP NetWeaver Application Server Java=7.20
SAP NetWeaver Application Server Java=7.30
SAP NetWeaver Application Server Java=7.31
SAP NetWeaver Application Server Java=7.40
SAP NetWeaver Application Server Java=7.50
Event History
Sep 14, 2021
CVE Published
via MITRE·11:21 AM
Data Sourced
via MITRE·11:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 25, 58461
Event
06:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2021-37535?
The severity of CVE-2021-37535 is critical with a CVSS score of 9.8.
2
Which versions of SAP NetWeaver Application Server Java are affected by CVE-2021-37535?
The affected versions of SAP NetWeaver Application Server Java are 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
3
What is the description of CVE-2021-37535?
CVE-2021-37535 is a vulnerability in SAP NetWeaver Application Server Java (JMS Connector Service) that allows unauthorized access due to missing authorization checks.
4
How can I fix CVE-2021-37535?
To fix CVE-2021-37535, update to a patched version of SAP NetWeaver Application Server Java.
5
Where can I find more information about CVE-2021-37535?
You can find more information about CVE-2021-37535 in the SAP Note 3078609 and the SAP Community Wiki page.