CVE-2021-38164
Estado: ModificadaMedia (5.4)—
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.48%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
- CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-38164",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "cna@sap.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP SE",
"product": "SAP ERP Financial Accounting (RFOPENPOSTING_FR)",
"versions": [
{
"status": "affected",
"version": "< SAP_APPL - 600"
},
{
"status": "affected",
"version": "< 602"
},
{
"status": "affected",
"version": "< 603"
},
{
"status": "affected",
"version": "< 604"
},
{
"status": "affected",
"version": "< 605"
},
{
"status": "affected",
"version": "< 606"
},
{
"status": "affected",
"version": "< 616"
},
{
"status": "affected",
"version": "< SAP_FIN - 617"
},
{
"status": "affected",
"version": "< 618"
},
{
"status": "affected",
"version": "< 700"
},
{
"status": "affected",
"version": "< 720"
},
{
"status": "affected",
"version": "< 730"
},
{
"status": "affected",
"version": "< SAPSCORE - 125"
},
{
"status": "affected",
"version": "< S4CORE"
},
{
"status": "affected",
"version": "< 100"
},
{
"status": "affected",
"version": "< 101"
},
{
"status": "affected",
"version": "< 102"
},
{
"status": "affected",
"version": "< 103"
},
{
"status": "affected",
"version": "< 104"
},
{
"status": "affected",
"version": "< 105"
}
]
}
]
}
],
"published": "2021-09-14T12:15:10.963",
"references": [
{
"url": "https://launchpad.support.sap.com/#/notes/3068582",
"tags": [
"Permissions Required"
],
"source": "cna@sap.com"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/3068582",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@sap.com",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to."
},
{
"lang": "es",
"value": "SAP ERP Financial Accounting (RFOPENPOSTING_FR) versiones - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, permiten a un atacante registrado invocar determinadas funciones que de otro modo estarían restringidas a usuarios específicos. Estas funciones suelen estar expuestas a través de la red y, una vez explotadas, el atacante puede ser capaz de visualizar y modificar datos de contabilidad financiera a los que sólo debería tener acceso un usuario específico"
}
],
"lastModified": "2026-06-17T04:01:39.540",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:100:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B5FED0E-F340-413A-B047-1CD17E912505"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:101:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6C0BF45-AADF-4CBD-ABC0-0D23AFD63BAD"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:102:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BA76D68-91A6-43F2-A812-FB33879B5F8B"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:103:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C4A9B55-E8E4-4B6E-B76A-FD7BA1E00A6B"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:104:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0743B7E3-325C-46C0-8466-AD6EAB89DEBA"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:105:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "23B4086D-C7DB-4B88-8FCE-D95A4BE68854"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:602:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F697EDC-D24F-46F8-AFE8-6F0FFA780279"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:603:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62485182-31FF-4DB6-8DF0-20405D859E23"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:604:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64A6C2AC-2A12-4143-A46B-8EDE8D9B612D"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:605:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60F84DC8-664D-4B27-8440-43C4F5C21033"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:606:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "853990B2-777E-4A6E-A85E-053891A04015"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:616:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A7C3205-BBA6-4C28-B4CE-740829D3A98C"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:618:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3C2AF1E-8905-4039-8376-3BB81F2E0245"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:700:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB2789AF-3FAE-467A-9296-B33CD953231E"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:720:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9F9A4B4-B1CC-462D-9A04-328C067CBEE2"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:730:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98A55DFC-B5B1-4EA3-9E71-2BC5696E3A02"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:s4core:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41BA91BC-778C-403F-BDD8-24321E834AE4"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:sap_appl_-_600:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93B22960-628F-484D-8442-E378D491817E"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:sap_fin_-_617:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35A552DC-87FF-4781-A613-621B4DA27721"
},
{
"criteria": "cpe:2.3:a:sap:erp_financial_accounting:sapscore_-_125:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "618D82D7-3DF6-4932-A2C7-82F34A12EE86"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}