Skip to content
COOEY

EXPOSURES › CVE-2021-38163

CVE-2021-38163

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-38163 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

SAP NetWeaver's unrestricted file upload vulnerability allows attackers to upload arbitrary files, potentially leading to system compromise and data exfiltration.

A vulnerability in SAP NetWeaver allows unrestricted file uploads, enabling attackers to potentially execute malicious code or compromise sensitive data; DIB organizations using NetWeaver must immediately patch and review file upload configurations to prevent exploitation and maintain CMMC compliance.

Shame score — The unrestricted file upload represents a significant design flaw with potentially severe consequences, demonstrating a lack of basic security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP NetWeaver contains a vulnerability that allows unrestricted file upload.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized