CVE-2021-44235 Information

Description

Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700 701 702 710 711 730 731 740 750 751 752 753 754 755 756 allow an attacker with high privileges and has direct access to SAP System to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system that could highly impact the Confidentiality Integrity and Availability of the system.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Reference

https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021 https://launchpad.support.sap.com/#/notes/3123196

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

6.7

Share on: