peter bassill · operator
$ cve CVE-2021-38163 JSON

CVE-2021-38163 KEV

9.9
CRITICAL · CVSS 3.1 · EPSS 36% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-30.

Description

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS36.02% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-06-30
Public exploitnone known
Published2021-09-14
Last modified2026-06-17

CISA KEV

NameSAP NetWeaver Unrestricted File Upload Vulnerability
Added2022-06-09
Due2022-06-30
Vendor / productSAP / NetWeaver
Ransomware usenone reported

Affected (1)

VendorProduct
sapnetweaver

References

→ the Explorer  ·  watch your stack  ·  NVD