First published: Tue Oct 12 2021(Updated: )
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP | =700 | |
SAP NetWeaver AS ABAP | =701 | |
SAP NetWeaver AS ABAP | =702 | |
SAP NetWeaver AS ABAP | =730 | |
SAP NetWeaver AS ABAP | =731 | |
SAP NetWeaver AS ABAP | =740 | |
SAP NetWeaver AS ABAP | =750 | |
SAP NetWeaver AS ABAP | =751 | |
SAP NetWeaver AS ABAP | =752 | |
SAP NetWeaver AS ABAP | =753 | |
SAP NetWeaver AS ABAP | =754 | |
SAP NetWeaver AS ABAP | =755 | |
SAP NetWeaver AS ABAP | =756 | |
SAP NetWeaver AS ABAP | =785 | |
SAP NetWeaver AS ABAP | =700 | |
SAP NetWeaver AS ABAP | =701 | |
SAP NetWeaver AS ABAP | =702 | |
SAP NetWeaver AS ABAP | =730 | |
SAP NetWeaver AS ABAP | =731 | |
SAP NetWeaver AS ABAP | =740 | |
SAP NetWeaver AS ABAP | =750 | |
SAP NetWeaver AS ABAP | =751 | |
SAP NetWeaver AS ABAP | =752 | |
SAP NetWeaver AS ABAP | =753 | |
SAP NetWeaver AS ABAP | =754 | |
SAP NetWeaver AS ABAP | =755 | |
SAP NetWeaver AS ABAP | =756 | |
SAP NetWeaver AS ABAP | =785 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-40496.
Versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, and 785 are affected.
The severity rating of CVE-2021-40496 is medium with a value of 4.3.
An attacker with logon functionality can exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request.
You can find more information about CVE-2021-40496 at the following references: [SAP Support Note](https://launchpad.support.sap.com/#/notes/3087254) and [SAP Community Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983).