« Volver al listado

CVE-2021-27617

Estado: ModificadaMedia (4.9)—

The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service conditions due to consumption of a large amount of system memory, thus highly impacting system availability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27617",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP Process Integration (Integration Builder Framework)",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.10"
            },
            {
              "status": "affected",
              "version": "< 7.11"
            },
            {
              "status": "affected",
              "version": "< 7.20"
            },
            {
              "status": "affected",
              "version": "< 7.30"
            },
            {
              "status": "affected",
              "version": "< 7.31"
            },
            {
              "status": "affected",
              "version": "< 7.40"
            },
            {
              "status": "affected",
              "version": "< 7.50"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-05-11T15:15:08.410",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/3012021",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/3012021",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service conditions due to consumption of a large amount of system memory, thus highly impacting system availability."
    },
    {
      "lang": "es",
      "value": "Integration Builder Framework de SAP Process Integration versiones - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, no comprueba suficientemente un documento XML cargado desde una fuente local.&#xa0;Un atacante puede crear un XML malicioso que, cuando la aplicación lo carga y lo analiza, podría conllevar a condiciones de Denegación de Servicio debido al consumo de una gran cantidad de memoria del sistema, impactando altamente la disponibilidad del sistema"
    }
  ],
  "lastModified": "2026-06-17T03:45:14.353",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75E83C25-D30B-4459-A1F1-DE7EC9FD46BE"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "900D10B0-B47B-46B0-A0A9-8E41660429DD"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D57CEB9D-5C06-4B3E-A36E-5B8689CA5657"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3062CE84-B6E2-40DE-B7B1-0752FC21BFAD"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "587D81FB-B2ED-4184-9258-A38A18B36DC5"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A325699D-6AB0-4BBC-A21C-A974FA1612DE"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A3A3226-28D1-4B43-942B-F41BD340E746"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}