CVE-2021-21473
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.
- Affected products
- Abap Platform, Sap Netweaver As Abap
- Sap Netweaver Application Server Abap
- = 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- CVSS 3.1
- 6.3 MEDIUM
- EPSS
- 1.2% (67th percentile)
- Weakness
- CWE-862
- NVD status
- Modified
- Published
- 2021-06-09
CVE-2021-21473 at NVD
1 known exploit for CVE-2021-21473
Proof-of-concept code and exploit modules indexed by Sploitus