SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-38163

SAP NetWeaver Unrestricted File Upload Vulnerability

KEVHIGH 8.8EPSS 36.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
36.02% probability · 98th percentile
CISA KEV
Listed 9 June 2022 · due 30 June 2022
Weakness
CWE-22
Affected
sap/netweaver
Source
cna@sap.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-38163

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.