CVE-2021-21469 Information
Description
When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g. MDS Server password not set network and OS configuration not properly secured etc.) a malicious user might define UNC paths which could then be exploited to put the system at risk using a so-called SMB relay attack and obtain highly sensitive data which leads to Information Disclosure.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476 https://launchpad.support.sap.com/#/notes/2993032
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: