CVE-2021-33701

CRITICAL

SAP DMIS and S/4HANA - Authenticated SQL Injection via NDZT Tool Query Manipulation

Title source: llm
STIX 2.1

Description

DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL Injection vulnerability, that highly impacts systems Confidentiality, Integrity and Availability.

References (6)

Core 6
Core References
Permissions Required, VDB Entry, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3078312
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Dec/36
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Dec/35

Scores

CVSS v3 9.1
EPSS 0.0125
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (14)
sap/dmis 710
sap/dmis 2011_1_620
sap/dmis 2011_1_640
sap/dmis 2011_1_700
sap/dmis 2011_1_710
sap/dmis 2011_1_730
sap/dmis 2011_1_731
sap/dmis 2011_1_752
sap/dmis 2020125
sap/s4core 102
... and 4 more
Published Sep 15, 2021
Tracked Since Feb 18, 2026