Lucene search

K
cvelistSapCVELIST:CVE-2021-21485
HistoryApr 13, 2021 - 6:44 p.m.

CVE-2021-21485

2021-04-1318:44:47
sap
www.cve.org
10
unauthorized access
sap netweaver
ntlm hashes

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.002

Percentile

53.4%

An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.

CNA Affected

[
  {
    "product": "SAP NetWeaver AS for JAVA (Telnet Commands)",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "ENGINEAPI 7.30, 7.31, 7.40, 7.50"
      },
      {
        "status": "affected",
        "version": "ESP_FRAMEWORK 7.10, 7.20, 7.30, 7.31, 7.40, 7.50"
      },
      {
        "status": "affected",
        "version": "SERVERCORE 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50"
      },
      {
        "status": "affected",
        "version": "J2EE-FRMW 7.10, 7.20, 7.30, 7.31, 7.40, 7.50"
      }
    ]
  }
]

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.002

Percentile

53.4%

Related for CVELIST:CVE-2021-21485