CVE-2021-33701
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL Injection vulnerability, that highly impacts systems Confidentiality, Integrity and Availability.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sap/dmis · sap/s4core · sap/sapscore
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/165303/SAP-Netweaver-IUUC_RECON_RC_COUNT_TABLE_BIG-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165304/SAP-Netweaver-IUUC_RECON_RC_COUNT_TABLE_BIG-ABAP-Code-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Dec/35Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Dec/36Exploit, Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3078312Permissions Required, VDB Entry, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806Vendor Advisory
- http://packetstormsecurity.com/files/165303/SAP-Netweaver-IUUC_RECON_RC_COUNT_TABLE_BIG-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165304/SAP-Netweaver-IUUC_RECON_RC_COUNT_TABLE_BIG-ABAP-Code-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Dec/35Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Dec/36Exploit, Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3078312Permissions Required, VDB Entry, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.