CVE-2021-33705
HIGHSAP NetWeaver Portal 7.10-7.50 - Unauthenticated Server-Side Request Forgery via Iviews Editor
Title source: llmDescription
The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) vulnerability which allows an unauthenticated attacker to craft a malicious URL which when clicked by a user can make any type of request (e.g. POST, GET) to any internal or external server. This can result in the accessing or modification of data accessible from the Portal but will not affect its availability.
References (4)
Core 4
Core References
Patch, Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/3074844
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/Jan/72
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/165743/SAP-Enterprise-Portal-iviewCatcherEditor-Server-Side-Request-Forgery.html
Scores
CVSS v3
8.1
EPSS
0.0069
EPSS Percentile
72.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Details
CWE
CWE-918
Status
published
Products (7)
sap/netweaver_portal
7.10
sap/netweaver_portal
7.11
sap/netweaver_portal
7.20
sap/netweaver_portal
7.30
sap/netweaver_portal
7.31
sap/netweaver_portal
7.40
sap/netweaver_portal
7.50
Published
Sep 15, 2021
Tracked Since
Feb 18, 2026