CVE-2021-33671

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/07/2021
Last modified:
16/07/2021

Description

SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. The impact of missing authorization could result to abuse of functionality restricted to a particular user group, and could allow unauthorized users to read, modify or delete restricted data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:netweaver_guided_procedures:7.10:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_guided_procedures:7.20:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_guided_procedures:7.30:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_guided_procedures:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_guided_procedures:7.40:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_guided_procedures:7.50:*:*:*:*:*:*:*