Lucene search

K
cveSapCVE-2021-21488
HistoryMar 09, 2021 - 3:15 p.m.

CVE-2021-21488

2021-03-0915:15:15
CWE-502
sap
web.nvd.nist.gov
22
cve-2021-21488
knowledge management
7.01
7.02
7.30
7.31
7.40
7.50
remote code execution
insecure deserialization
nvd
vulnerability

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

57.0%

Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability.

Affected configurations

Nvd
Node
sapnetweaver_knowledge_managementMatch7.01
OR
sapnetweaver_knowledge_managementMatch7.02
OR
sapnetweaver_knowledge_managementMatch7.30
OR
sapnetweaver_knowledge_managementMatch7.31
OR
sapnetweaver_knowledge_managementMatch7.40
OR
sapnetweaver_knowledge_managementMatch7.50
VendorProductVersionCPE
sapnetweaver_knowledge_management7.01cpe:2.3:a:sap:netweaver_knowledge_management:7.01:*:*:*:*:*:*:*
sapnetweaver_knowledge_management7.02cpe:2.3:a:sap:netweaver_knowledge_management:7.02:*:*:*:*:*:*:*
sapnetweaver_knowledge_management7.30cpe:2.3:a:sap:netweaver_knowledge_management:7.30:*:*:*:*:*:*:*
sapnetweaver_knowledge_management7.31cpe:2.3:a:sap:netweaver_knowledge_management:7.31:*:*:*:*:*:*:*
sapnetweaver_knowledge_management7.40cpe:2.3:a:sap:netweaver_knowledge_management:7.40:*:*:*:*:*:*:*
sapnetweaver_knowledge_management7.50cpe:2.3:a:sap:netweaver_knowledge_management:7.50:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SAP NetWeaver Knowledge Management",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 7.01"
      },
      {
        "status": "affected",
        "version": "< 7.02"
      },
      {
        "status": "affected",
        "version": "< 7.30"
      },
      {
        "status": "affected",
        "version": "< 7.31"
      },
      {
        "status": "affected",
        "version": "< 7.40"
      },
      {
        "status": "affected",
        "version": "< 7.50"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

57.0%

Related for CVE-2021-21488