launchpad.support.sap.com
https://launchpad.support.sap.com/ CVE-2021-38163
CRITICALCISA KEV
SAP NetWeaver Unrestricted File Upload Vulnerability
Record summary
CVE-2021-38163 has a selected CVSS score of 9.9 (critical); EIP currently links 2 repository PoCs. CISA lists CVE-2021-38163 in KEV.
Description
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jun 9, 2022 · CISA
- VulnCheck KEV
- Listed · Jun 9, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 2
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
NetWeaverBrowse SAP / NetWeaver | CISA | Version data not supplied | |
SAP NetWeaver (Visual Composer 7.0 RT)Browse SAP SE / SAP NetWeaver (Visual Composer 7.0 RT)Default status: unaffected | CVE List | 7.30 | affected |
| 7.31 | affected | ||
| 7.40 | affected | ||
| 7.50 | affected | ||
Proofs of concept
2Repository PoCs
GitHubcore1impact/CVE-2021-38163Repository PoCby core1impactStars: 4Not analyzed3 files
GitHubpurpleteam-ru/CVE-2021-38163Repository PoCby purpleteam-ruStars: 0Not analyzed3 files
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-38163 wiki.scn.sap.com
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38163