Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-33690

EPSS 93.26% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-33690

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
SAP NetWeaver 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAP NetWeaver Development Infrastructure是德国思爱普(SAP)公司的提供了一致的开发环境,开发团队,并支持软件开发贯穿产品的整个生命周期。 SAP NetWeaver Development Infrastructure 存在代码问题漏洞,该漏洞的存在是由于对用户提供的输入验证不足。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
SAP SESAP NetWeaver Development Infrastructure (Component Build Service) < 7.11 -

II. Public POCs for CVE-2021-33690

#POC DescriptionSource LinkShenlong Link
1[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructurehttps://github.com/redrays-io/CVE-2021-33690POC Details
2Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33690.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-33690

登录查看更多情报信息。

Same Patch Batch · SAP SE · 2021-09-15 · 13 CVEs total

CVE-2021-33696SAP ERP 跨站脚本漏洞
CVE-2021-33692SAP ERP 路径遍历漏洞
CVE-2021-33695SAP ERP 信任管理问题漏洞
CVE-2021-33697SAP ERP 安全漏洞
CVE-2021-33693SAP ERP 代码注入漏洞
CVE-2021-33691SAP NetWeaver 跨站脚本漏洞
CVE-2021-33694SAP ERP 跨站脚本漏洞
CVE-2021-33700SAP Business One 授权问题漏洞
CVE-2021-33705SAP Enterprise Portal 代码问题漏洞
CVE-2021-33698SAP Business One 代码问题漏洞
CVE-2021-33701SAP ERP SQL注入漏洞
CVE-2021-33704SAP Business One 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-33690

No comments yet


Leave a comment