// For flags

CVE-2021-33684

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.77, 7.81, 7.84, allows an attacker to send overlong content in the RFC request type thereby crashing the corresponding work process because of memory corruption vulnerability. The work process will attempt to restart itself after the crash and hence the impact on the availability is low.

SAP NetWeaver AS ABAP y ABAP Platform, versiones - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7. 53, KERNEL 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.77, 7.81, 7.84, permite a un atacante enviar contenido excesivamente largo en el tipo de petición RFC, bloqueando así el proceso de trabajo correspondiente debido a una vulnerabilidad de corrupción de memoria. El proceso de trabajo intentará reiniciarse por sí mismo después del bloqueo y, por lo tanto, el impacto en la disponibilidad es bajo

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-05-28 CVE Reserved
  • 2021-07-14 CVE Published
  • 2024-03-29 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.21
Search vendor "Sap" for product "Netweaver Abap" and version "7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.21ext
Search vendor "Sap" for product "Netweaver Abap" and version "7.21ext"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.22
Search vendor "Sap" for product "Netweaver Abap" and version "7.22"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.22ext
Search vendor "Sap" for product "Netweaver Abap" and version "7.22ext"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.49
Search vendor "Sap" for product "Netweaver Abap" and version "7.49"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.53
Search vendor "Sap" for product "Netweaver Abap" and version "7.53"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.77
Search vendor "Sap" for product "Netweaver Abap" and version "7.77"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
7.81
Search vendor "Sap" for product "Netweaver Abap" and version "7.81"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
kernel_8.04
Search vendor "Sap" for product "Netweaver Abap" and version "kernel_8.04"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl32nuc_7.21
Search vendor "Sap" for product "Netweaver Abap" and version "krnl32nuc_7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl32uc_7.21
Search vendor "Sap" for product "Netweaver Abap" and version "krnl32uc_7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64nuc_7.21
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64nuc_7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Abap
Search vendor "Sap" for product "Netweaver Abap"
krnl64uc_8.04
Search vendor "Sap" for product "Netweaver Abap" and version "krnl64uc_8.04"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.21
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.21ext
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.21ext"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.22
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.22"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.22ext
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.22ext"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.49
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.49"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.53
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.53"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.77
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.77"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
7.81
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "7.81"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
kernel_8.04
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_8.04"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
krnl32nuc_7.21
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "krnl32nuc_7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
krnl32uc_7.21
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "krnl32uc_7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
krnl64nuc_7.21
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "krnl64nuc_7.21"
-
Affected
Sap
Search vendor "Sap"
Netweaver Application Server Abap
Search vendor "Sap" for product "Netweaver Application Server Abap"
krnl64uc_8.04
Search vendor "Sap" for product "Netweaver Application Server Abap" and version "krnl64uc_8.04"
-
Affected