Skip to content

Commit

Permalink
Update CVE-2021-33690.yaml
Browse files Browse the repository at this point in the history
  • Loading branch information
ritikchaddha authored Nov 16, 2023
1 parent d6f5c2a commit 00ba237
Showing 1 changed file with 4 additions and 5 deletions.
9 changes: 4 additions & 5 deletions http/cves/2021/CVE-2021-33690.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,9 @@ info:
name: SAP NetWeaver Development Infrastructure - Server Side Request Forgery
author: DhiyaneshDK
severity: critical
remediation: Apply the latest firmware update provided by the vendor to mitigate this vulnerability.
description: |
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.
remediation: |
Apply the latest firmware update provided by the vendor to mitigate this vulnerability.
reference:
- https://redrays.io/cve-2021-33690-server-side-request-forgery-vulnerability/
- https://nvd.nist.gov/vuln/detail/CVE-2021-33690
Expand All @@ -20,11 +19,11 @@ info:
epss-percentile: 0.4388
cpe: cpe:2.3:a:sap:netweaver_development_infrastructure:7.11:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
verified: true
shodan-query: html:"SAP NetWeaver"
vendor: sap
product: netweaver_development_infrastructure
shodan-query: html:"SAP NetWeaver"
tags: cve,cve2021,oast,ssrf,sap

http:
Expand All @@ -39,7 +38,7 @@ http:
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol # Confirms the HTTP Interaction
part: interactsh_protocol
words:
- "dns"

Expand Down

0 comments on commit 00ba237

Please sign in to comment.