VDB

CVE-2021-38176

CVE-2021-38176 PUBLISHED CVSS 9.899999618530273 CRITICAL

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.

EPSS 0.72% · 72.9th percentile

Risk Scores

CVSS 3.0
9.899999618530273
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.72%
72.9th percentile

Affected Products

VendorProductVersions
SAP SESAP Landscape Transformation< 2.0
SAP SESAP Test Data Migration Server< 4.0
SAP SESAP LTRS for S/4HANA< 1.0
saptest_data_migration_server4.0
SAP SESAP S/4HANA< 1909, < 2020, < 2021
saps\/4hana2020, 1610, 1511
saplandscape_transformation_replication_server1.0, 2.0, 3.0
SAP SESAP LT Replication Server*, < 2.0
saplandscape_transformation2.0

Timeline

  • Sep 14, 2021 CVE Published
  • Sep 15, 2021 EPSS Score
  • Oct 5, 2021 EPSS Score
  • Nov 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 8, 2022 EPSS Score
  • Mar 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 3, 2022 EPSS Score
  • Jun 29, 2022 EPSS Score
  • Oct 23, 2022 EPSS Score
  • Dec 20, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›