CVE-2021-38176
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sap/landscape transformation · sap/landscape transformation replication server · sap/s\/4hana · sap/test data migration server
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/3089831Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3089831Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.