EXPOSURES › CVE-2021-38163
CVE-2021-38163
HIGH ⌖ ON CISA KEV · EXPLOITEDSAP NetWeaver's unrestricted file upload vulnerability allows attackers to upload arbitrary files, potentially leading to system compromise and data exfiltration.
A vulnerability in SAP NetWeaver allows unrestricted file uploads, enabling attackers to potentially execute malicious code or compromise sensitive data; DIB organizations using NetWeaver must immediately patch and review file upload configurations to prevent exploitation and maintain CMMC compliance.
Shame score — The unrestricted file upload represents a significant design flaw with potentially severe consequences, demonstrating a lack of basic security controls.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |