Lucene search

K
cveSapCVE-2021-21469
HistoryJan 12, 2021 - 3:15 p.m.

CVE-2021-21469

2021-01-1215:15:16
CWE-200
sap
web.nvd.nist.gov
32
4
sap netweaver
master data management
windows
security
information disclosure
smb relay attack
nvd
cve-2021-21469

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

55.1%

When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g., MDS Server password not set, network and OS configuration not properly secured, etc.), a malicious user might define UNC paths which could then be exploited to put the system at risk using a so-called SMB relay attack and obtain highly sensitive data, which leads to Information Disclosure.

Affected configurations

Nvd
Node
sapnetweaver_master_data_managementMatch7.10
OR
sapnetweaver_master_data_managementMatch7.10.750
OR
sapnetweaver_master_data_managementMatch710
VendorProductVersionCPE
sapnetweaver_master_data_management7.10cpe:2.3:a:sap:netweaver_master_data_management:7.10:*:*:*:*:*:*:*
sapnetweaver_master_data_management7.10.750cpe:2.3:a:sap:netweaver_master_data_management:7.10.750:*:*:*:*:*:*:*
sapnetweaver_master_data_management710cpe:2.3:a:sap:netweaver_master_data_management:710:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SAP NetWeaver Master Data Management",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 7.10"
      },
      {
        "status": "affected",
        "version": "< 710"
      },
      {
        "status": "affected",
        "version": "< 710.750"
      }
    ]
  }
]

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

55.1%

Related for CVE-2021-21469