First published: Tue Oct 12 2021(Updated: )
The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the confidentiality, integrity, and availability of the system and its data.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP | =700 | |
SAP NetWeaver AS ABAP | =701 | |
SAP NetWeaver AS ABAP | =702 | |
SAP NetWeaver AS ABAP | =710 | |
SAP NetWeaver AS ABAP | =730 | |
SAP NetWeaver AS ABAP | =731 | |
SAP NetWeaver AS ABAP | =740 | |
SAP NetWeaver AS ABAP | =750 | |
SAP NetWeaver AS ABAP | =751 | |
SAP NetWeaver AS ABAP | =752 | |
SAP NetWeaver AS ABAP | =753 | |
SAP NetWeaver AS ABAP | =754 | |
SAP NetWeaver AS ABAP | =755 | |
SAP NetWeaver AS ABAP | =756 | |
SAP NetWeaver AS ABAP | =700 | |
SAP NetWeaver AS ABAP | =701 | |
SAP NetWeaver AS ABAP | =702 | |
SAP NetWeaver AS ABAP | =710 | |
SAP NetWeaver AS ABAP | =730 | |
SAP NetWeaver AS ABAP | =731 | |
SAP NetWeaver AS ABAP | =740 | |
SAP NetWeaver AS ABAP | =750 | |
SAP NetWeaver AS ABAP | =751 | |
SAP NetWeaver AS ABAP | =752 | |
SAP NetWeaver AS ABAP | =753 | |
SAP NetWeaver AS ABAP | =754 | |
SAP NetWeaver AS ABAP | =755 | |
SAP NetWeaver AS ABAP | =756 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38178 is high with a CVSS score of 8.8.
CVE-2021-38178 affects SAP NetWeaver ABAP and ABAP Platform versions 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756.
CVE-2021-38178 enables a malicious user to transfer ABAP code artifacts or content, bypassing quality gates.
To fix CVE-2021-38178, apply the necessary patches provided by SAP and follow the recommendations in the SAP Security Note.
You can find more information about CVE-2021-38178 in the SAP Security Note and the SAP Community Network (SCN) wiki.