SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-01-29T20:20:05.172Z
Reserved: 2021-08-07T00:00:00.000Z
Link: CVE-2021-38163

Updated: 2024-08-04T01:37:16.194Z

Status : Modified
Published: 2021-09-14T12:15:10.890
Modified: 2025-01-29T21:15:11.597
Link: CVE-2021-38163

No data.