CVE-2021-33678 PUBLISHED CVSS 6.5 MEDIUM

A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.

EPSS 2.16% · 84.2th percentile

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS Score
2.16%
84.2th percentile

Affected Products

VendorProductVersions
sapnetweaver_application_server_abap752, 75a, 75b
SAP SESAP NetWeaver AS ABAP (Reconciliation Framework)< 700, < 701, < 702

Timeline

References

Open in Interactive Console →