Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21482

Опубликовано: 13 апр. 2021
Источник: nvd
CVSS3: 8.3
CVSS3: 8.3
CVSS2: 4.8
EPSS Низкий

Описание

SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information disclosure vulnerability thereby affecting the confidentiality and integrity of the application. This happens when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:netweaver_master_data_management:7.10.750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_master_data_management:710:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00092
Низкий

8.3 High

CVSS3

8.3 High

CVSS3

4.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.3
github
больше 3 лет назад

SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information disclosure vulnerability thereby affecting the confidentiality and integrity of the application. This happens when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.

EPSS

Процентиль: 26%
0.00092
Низкий

8.3 High

CVSS3

8.3 High

CVSS3

4.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo