VulnerabilityModified
CVE-2021-40495
There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755.
MEDIUM 5.3EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755. An unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP NetWeaver Application Server ABAP and ABAP Platform.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- sap/netweaver abap · sap/netweaver application server abap
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/3099011Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3099011Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.