CVE-2021-38163: SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
Other sources
SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38163?
The severity of CVE-2021-38163 is critical with a CVSS score of 8.8.
How does CVE-2021-38163 impact SAP NetWeaver?
CVE-2021-38163 allows an authenticated non-administrative user to upload a malicious file over the network and run operating system commands with elevated privileges.
Which versions of SAP NetWeaver are affected by CVE-2021-38163?
The affected versions of SAP NetWeaver are 7.30, 7.31, 7.40, and 7.50.
How can I fix CVE-2021-38163?
To fix CVE-2021-38163, apply the necessary patches provided by SAP and follow their recommended guidance.
Where can I find more information about CVE-2021-38163?
You can find more information about CVE-2021-38163 in SAP Note 3084487 and the SAP NetWeaver wiki page.