Back to overview

CVE-2021-38163

CRITICAL KEV CISA Exploitation: ACTIVE
9.9
CVSS 3.1
Description
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

Metadata

CVE ID
CVE-2021-38163
State
PUBLISHED
Assigner
sap
Reserved
2021-08-07 00:00 UTC
Published
2021-09-14 11:21 UTC
Last updated
2025-10-21 23:25 UTC
Primary CWE
CWE-22
CWE-22 Improper Limitation of a Pathname to a Restricted Dir…
Vendor / Product
SAP SE / SAP NetWeaver (Visual Composer 7.0 RT)
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
no
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
SAP NetWeaver Unrestricted File Upload Vulnerability
Vendor
SAP
Product
NetWeaver
Added to KEV
2022-06-09
Due date
2022-06-30
Ransomware
Not known
Required action
Apply updates per vendor instructions.
CISA description
SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
Affected products (1)
VendorProductPlatformVersions
SAP SE SAP NetWeaver (Visual Composer 7.0 RT) 7.30, 7.31, 7.40, 7.50
Weakness (CWE)
CWESourceDescription
cna Unrestricted File Upload
CWE-22 adp CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview