CVE-2021-38163 Information
Jun 07, 2022
cve
Description
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30 7.31 7.40 7.50 without restriction an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 https://launchpad.support.sap.com/#/notes/3084487
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: