// For flags

CVE-2021-33701

SAP Netweaver IUUC_RECON_RC_COUNT_TABLE_BIG ABAP Code Injection

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL Injection vulnerability, that highly impacts systems Confidentiality, Integrity and Availability.

DMIS Mobile Plug-In o SAP S/4HANA, versiones - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, permite a un atacante con acceso a una cuenta altamente privilegiada ejecutar una consulta manipulada en la herramienta NDZT para conseguir acceso a la cuenta Superuser, conllevando a una vulnerabilidad de Inyección SQL, que presenta un gran impacto en la Confidencialidad, Integridad y Disponibilidad de los sistemas

SAP Netweaver suffers from a remote ADBC SQL injection vulnerability in IUUC_RECON_RC_COUNT_TABLE_BIG. Other software and various versions are also affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-05-28 CVE Reserved
  • 2021-09-15 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-09-18 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
710
Search vendor "Sap" for product "Dmis" and version "710"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2011_1_620
Search vendor "Sap" for product "Dmis" and version "2011_1_620"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2011_1_640
Search vendor "Sap" for product "Dmis" and version "2011_1_640"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2011_1_700
Search vendor "Sap" for product "Dmis" and version "2011_1_700"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2011_1_710
Search vendor "Sap" for product "Dmis" and version "2011_1_710"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2011_1_730
Search vendor "Sap" for product "Dmis" and version "2011_1_730"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2011_1_731
Search vendor "Sap" for product "Dmis" and version "2011_1_731"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2011_1_752
Search vendor "Sap" for product "Dmis" and version "2011_1_752"
-
Affected
Sap
Search vendor "Sap"
Dmis
Search vendor "Sap" for product "Dmis"
2020125
Search vendor "Sap" for product "Dmis" and version "2020125"
-
Affected
Sap
Search vendor "Sap"
S4core
Search vendor "Sap" for product "S4core"
102
Search vendor "Sap" for product "S4core" and version "102"
-
Affected
Sap
Search vendor "Sap"
S4core
Search vendor "Sap" for product "S4core"
103
Search vendor "Sap" for product "S4core" and version "103"
-
Affected
Sap
Search vendor "Sap"
S4core
Search vendor "Sap" for product "S4core"
104
Search vendor "Sap" for product "S4core" and version "104"
-
Affected
Sap
Search vendor "Sap"
S4core
Search vendor "Sap" for product "S4core"
105
Search vendor "Sap" for product "S4core" and version "105"
-
Affected
Sap
Search vendor "Sap"
Sapscore
Search vendor "Sap" for product "Sapscore"
125
Search vendor "Sap" for product "Sapscore" and version "125"
-
Affected