CVE-2021-44235

Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system, that could highly impact the Confidentiality, Integrity and Availability of the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:756:*:*:*:*:*:*:*

History

06 Oct 2022, 15:09

Type Values Removed Values Added
First Time Sap netweaver Application Server Abap
CPE cpe:2.3:a:sap:netweaver_application_server_for_abap:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:752:*:*:*:*:*:*:*

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-94 CWE-78

16 Dec 2021, 18:50

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 6.7
CPE cpe:2.3:a:sap:netweaver_application_server_for_abap:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_for_abap:751:*:*:*:*:*:*:*
CWE CWE-94
References (MISC) https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021 - (MISC) https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021 - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3123196 - (MISC) https://launchpad.support.sap.com/#/notes/3123196 - Permissions Required

14 Dec 2021, 16:35

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-14 16:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-44235

Mitre link : CVE-2021-44235

CVE.ORG link : CVE-2021-44235


JSON object : View

Products Affected

sap

  • netweaver_application_server_abap
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')