CVE-2021-33690
97Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 9.9epss 68%
de la publicación al arma624 días
Publicada en NVD15 sept
1ª PoC+624d
VulnCheck+859d
probabilidad de explotación
68%top 1% de las CVE
explotación observada
síVulnCheck
2 exploit(s) público(s)
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
SAP SE · SAP NetWeaver Development Infrastructure (Component Build Service)PoCs públicas encontradas — 2
githubgithub.com/redrays-io/CVE-2021-33690★ 0vulncheckvulncheck.com/xdb/630fafc66ffdno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.