CVE-2021-21482
HIGHSAP NetWeaver Master Data Management 710, 710.750 - Unauthenticated Password Brute Force
Title source: llmDescription
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information disclosure vulnerability thereby affecting the confidentiality and integrity of the application. This happens when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.
References (2)
Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/3017908
Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649
Scores
CVSS v3
8.3
EPSS
0.0009
EPSS Percentile
25.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Details
Status
published
Products (2)
sap/netweaver_master_data_management
7.10.750
sap/netweaver_master_data_management
710
Published
Apr 13, 2021
Tracked Since
Feb 18, 2026