CVE-2021-38178

HIGH

SAP NetWeaver AS/ABAP Platform - Code Injection

Title source: llm
STIX 2.1

Description

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the confidentiality, integrity, and availability of the system and its data.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/3097887

Scores

CVSS v3 8.8
EPSS 0.0054
EPSS Percentile 67.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (28)
sap/netweaver_abap 700
sap/netweaver_abap 701
sap/netweaver_abap 702
sap/netweaver_abap 710
sap/netweaver_abap 730
sap/netweaver_abap 731
sap/netweaver_abap 740
sap/netweaver_abap 750
sap/netweaver_abap 751
sap/netweaver_abap 752
... and 18 more
Published Oct 12, 2021
Tracked Since Feb 18, 2026