Логотип exploitDog
bind:CVE-2021-38163
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-38163

Количество 3

Количество 3

nvd логотип

CVE-2021-38163

больше 4 лет назад

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS3: 9.9
EPSS: Высокий
github логотип

GHSA-px4v-wj8p-cq36

больше 3 лет назад

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS3: 8.8
EPSS: Высокий
fstec логотип

BDU:2021-04978

больше 4 лет назад

Уязвимость инструмента моделирования на основе браузера Visual Composer программной интеграционной платформы SAP NetWeaver, позволяющая нарушителю повысить свои привилегии, выполнить произвольные команды или вызвать отказ в обслуживании

CVSS3: 9.9
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-38163

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS3: 9.9
85%
Высокий
больше 4 лет назад
github логотип
GHSA-px4v-wj8p-cq36

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS3: 8.8
85%
Высокий
больше 3 лет назад
fstec логотип
BDU:2021-04978

Уязвимость инструмента моделирования на основе браузера Visual Composer программной интеграционной платформы SAP NetWeaver, позволяющая нарушителю повысить свои привилегии, выполнить произвольные команды или вызвать отказ в обслуживании

CVSS3: 9.9
85%
Высокий
больше 4 лет назад

Уязвимостей на страницу