CVE-2021-33705
The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) vulnerability which allows an unauthenticated attacker to craft a malicious URL which when clicked by a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) vulnerability which allows an unauthenticated attacker to craft a malicious URL which when clicked by a user can make any type of request (e.g. POST, GET) to any internal or external server. This can result in the accessing or modification of data accessible from the Portal but will not affect its availability.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 2.07% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- sap/netweaver portal
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/165743/SAP-Enterprise-Portal-iviewCatcherEditor-Server-Side-Request-Forgery.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jan/72Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3074844Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806Patch, Vendor Advisory
- http://packetstormsecurity.com/files/165743/SAP-Enterprise-Portal-iviewCatcherEditor-Server-Side-Request-Forgery.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jan/72Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/3074844Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.