CVE-2021-21472

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
09/02/2021
Last modified:
08/08/2023

Description

SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:software_provisioning_manager:1.0:*:*:*:*:*:*:*