CVE-2021-44235
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system, that could highly impact the Confidentiality, Integrity and Availability of the system.
Dos métodos de una clase de utilidad en SAP NetWeaver AS ABAP - versiones 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, permiten a un atacante con altos privilegios y que tenga acceso directo al sistema SAP, inyectar código cuando es ejecutado con un determinado constructor de clases de transacción. Esto podría permitir la ejecución de comandos arbitrarios en el sistema operativo, que podrían impactar altamente la Confidencialidad, Integridad y Disponibilidad del sistema
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-26 CVE Reserved
- 2021-12-14 CVE Published
- 2023-07-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021 | 2022-10-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 700 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "700" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 701 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "701" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 702 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "702" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 710 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "710" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 711 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "711" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 730 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "730" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 731 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "731" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 740 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "740" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 750 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "750" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 751 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "751" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 752 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "752" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 753 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "753" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 754 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "754" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 755 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "755" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | 756 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "756" | - |
Affected
|