CVE-2021-38176: SQL Injection
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38176?
CVE-2021-38176 has been identified as a high severity vulnerability due to the potential for remote code execution.
How can I fix CVE-2021-38176?
To fix CVE-2021-38176, update the affected SAP software to the latest version as provided in the vendor's security notes.
What versions of SAP software are affected by CVE-2021-38176?
CVE-2021-38176 affects multiple versions of SAP Landscape Transformation, SAP S/4HANA, and SAP Test Data Migration Server.
What impact does CVE-2021-38176 have on system security?
The exploitation of CVE-2021-38176 can allow an authenticated user to execute unauthorized queries or inject code, potentially compromising database security.
Who can exploit CVE-2021-38176?
CVE-2021-38176 can be exploited by an authenticated user with specific privileges within the affected SAP systems.