5.8

CVE-2021-33663

SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attacker to insert cleartext commands due to improper restriction of I/O buffering into encrypted SMTP sessions over the network which can partially impact the integrity of the application.

Data is provided by the National Vulnerability Database (NVD)
SAPNetweaver Application Server Abap Versionkernel_7.22
SAPNetweaver Application Server Abap Versionkernel_7.49
SAPNetweaver Application Server Abap Versionkernel_7.53
SAPNetweaver Application Server Abap Versionkernel_7.73
SAPNetweaver Application Server Abap Versionkernel_7.77
SAPNetweaver Application Server Abap Versionkernel_7.81
SAPNetweaver Application Server Abap Versionkernel_7.82
SAPNetweaver Application Server Abap Versionkernel_7.83
SAPNetweaver Application Server Abap Versionkernel_7.84
SAPNetweaver Application Server Abap Versionkernel_8.04
SAPNetweaver Application Server Abap Versionkrnl32nuc_7.22
SAPNetweaver Application Server Abap Versionkrnl32nuc_7.22ext
SAPNetweaver Application Server Abap Versionkrnl32uc_7.22
SAPNetweaver Application Server Abap Versionkrnl32uc_7.22ext
SAPNetweaver Application Server Abap Versionkrnl64nuc_7.22
SAPNetweaver Application Server Abap Versionkrnl64nuc_7.22ext
SAPNetweaver Application Server Abap Versionkrnl64nuc_7.49
SAPNetweaver Application Server Abap Versionkrnl64uc_7.22
SAPNetweaver Application Server Abap Versionkrnl64uc_7.22ext
SAPNetweaver Application Server Abap Versionkrnl64uc_7.49
SAPNetweaver Application Server Abap Versionkrnl64uc_7.53
SAPNetweaver Application Server Abap Versionkrnl64uc_7.73
SAPNetweaver Application Server Abap Versionkrnl64uc_8.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.377
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
cna@sap.com 5.8 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N