CVE-2021-33678
Description
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.
Risk Information
Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
2.162
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 731 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 740 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 751 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 752 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 700 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 710 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 730 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 711 | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75a | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75b | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75c | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75d | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75e | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 702 | Windows |
| Vulnerabilities CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75f | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 710 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 711 | Windows |
| Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 730 | Windows |
| Vulnerabilities CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75a | Windows |
| Vulnerabilities CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75b | Windows |
| Vulnerabilities CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75c | Windows |
| Vulnerabilities CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75d | Windows |
| Vulnerabilities CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75e | Windows |
| Vulnerabilities CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75f | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75a | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75b | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75c | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75d | Windows |
| Vulnerabilities CVE-2020-6270,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75e | Windows |
| Vulnerabilities CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75f | Windows |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234