CVE-2021-21482

Published Apr 13, 2021

Last updated 2 years ago

Overview

Description
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information disclosure vulnerability thereby affecting the confidentiality and integrity of the application. This happens when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.
Source
cna@sap.com
NVD status
Analyzed

Social media

Hype score
Not currently trending

Risk scores

CVSS 3.1

Type
Primary
Base score
8.3
Impact score
5.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Severity
HIGH

CVSS 3.0

Type
Secondary
Base score
8.3
Impact score
5.5
Exploitability score
2.8
Vector string
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
4.8
Impact score
4.9
Exploitability score
6.5
Vector string
AV:A/AC:L/Au:N/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Configurations