CVE-2021-38176 PUBLISHED CVSS 9.899999618530273 CRITICAL

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.

EPSS 0.72% · 72.4th percentile

Risk Scores

CVSS v3.0
9.899999618530273
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.72%
72.4th percentile

Affected Products

VendorProductVersions
SAP SESAP Landscape Transformation< 2.0
SAP SESAP Test Data Migration Server< 4.0
SAP SESAP LTRS for S/4HANA< 1.0
saptest_data_migration_server4.0
SAP SESAP S/4HANA< 1909, < 2020, < 2021
saps\/4hana1909, 2021, 1709
saplandscape_transformation_replication_server1.0, 2.0, 3.0
SAP SESAP LT Replication Server< 2.0, < 3.0
saplandscape_transformation2.0

Timeline

References

Open in Interactive Console →