Record summary

CVE-2021-38163 has a selected CVSS score of 9.9 (critical); EIP currently links 2 repository PoCs. CISA lists CVE-2021-38163 in KEV.

Description

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jun 9, 2022 · CISA
VulnCheck KEV
Listed · Jun 9, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

SAP NetWeaver (Visual Composer 7.0 RT)

Browse SAP SE / SAP NetWeaver (Visual Composer 7.0 RT)

Default status: unaffected

CVE List7.30affected
7.31affected
7.40affected
7.50affected

Proofs of concept

2

Repository PoCs

GitHubcore1impact/CVE-2021-38163Repository PoCby core1impactStars: 4Not analyzed3 files

11.3 KiB

GitHub

PoC details
GitHubpurpleteam-ru/CVE-2021-38163Repository PoCby purpleteam-ruStars: 0Not analyzed3 files

20.2 KiB

GitHub

PoC details

References

4