← Back to CVE List
Vulnerability Intelligence Report
SAP NetWeaver Unrestricted File Upload Vulnerability

CVE-2021-38163

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:37.15%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
SAP SE SAP NetWeaver (Visual Composer 7.0 RT) 7.30 (affected), 7.31 (affected), 7.40 (affected), 7.50 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
37.149%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2021-08-07T00:00:00
Published2021-09-14T11:21:36
Last Updated2025-10-21T23:25:33

LINK COPIED TO CLIPBOARD