CVE-2021-33670
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.16% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- sap/netweaver application server java
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/166965/SAP-NetWeaver-Java-Denial-Of-Service.htmlPatch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/May/4Mailing List, Patch, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3056652Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506Vendor Advisory
- http://packetstormsecurity.com/files/166965/SAP-NetWeaver-Java-Denial-Of-Service.htmlPatch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/May/4Mailing List, Patch, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3056652Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.