Record summary

CVE-2021-33690 has a selected CVSS score of 9.9 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

SAP NetWeaver Development Infrastructure (Component Build Service)

Browse SAP SE / SAP NetWeaver Development Infrastructure (Component Build Service)
CVE List< 7.11affected
< 7.20affected
< 7.30affected
< 7.31affected
< 7.40affected
< 7.50affected

Proofs of concept

1

Repository PoCs

GitHubredrays-io/CVE-2021-33690Repository PoCby redrays-ioStars: 0Not analyzed1 file

4.2 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALSAP NetWeaver Development Infrastructure - Server Side Request ForgeryCVSS 9.9

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.

Impact

Authenticated attackers can perform SSRF attacks to manipulate internal network resources, potentially accessing sensitive internal systems and data.

Remediation

Apply the latest firmware update provided by the vendor to mitigate this vulnerability.

WeaknessesCWE-918
AuthorsDhiyaneshDK
Template tagscve2021cveoastssrfsapvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CPE: cpe:2.3:a:sap:netweaver_development_infrastructure:7.11:*:*:*:*:*:*:*
Shodan: html:"SAP NetWeaver"
Shodan: http.html:"sap netweaver"
FOFA: body="sap netweaver"

Source: ProjectDiscovery

References

3