4.3

CVE-2021-40496

SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver Abap Version 700
SAP ≫ Netweaver Abap Version 701
SAP ≫ Netweaver Abap Version 702
SAP ≫ Netweaver Abap Version 730
SAP ≫ Netweaver Abap Version 731
SAP ≫ Netweaver Abap Version 740
SAP ≫ Netweaver Abap Version 750
SAP ≫ Netweaver Abap Version 751
SAP ≫ Netweaver Abap Version 752
SAP ≫ Netweaver Abap Version 753
SAP ≫ Netweaver Abap Version 754
SAP ≫ Netweaver Abap Version 755
SAP ≫ Netweaver Abap Version 756
SAP ≫ Netweaver Abap Version 785
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.95% 0.578
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983
Vendor Advisory
https://launchpad.support.sap.com/#/notes/3087254
Vendor Advisory
Permissions Required