CVE-2021-27635
CVE-2021-27635
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9EPSS 1.6%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
09 Jun 2021Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
Affected products
SAP SE · SAP NetWeaver AS for JAVApublic PoCs found — 1
cve_referencepacketstormsecurity.com/files/164592/SAP-JAVA-NetWeaver-System-Connections-XML-Injection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →