S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-33690 Scanner

CVE-2021-33690 scanner - Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-33690
9.9
CVSScritical
Exploitable remotely over the internet · low-privilege account sufficient.

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
SAP NetWeaver Development Infrastructure (Component Build Service)by SAP SE
< 7.11
Updated Aug 21, 2026View on NVD →
Detail

SAP NetWeaver Development Infrastructure is a crucial component for the development, provisioning, and management of SAP applications. This platform supports the entire lifecycle of software development with tools for modeling, designing, and managing SAP solutions. It is used by developers and IT professionals across various industries to streamline the development process of SAP applications, ensuring efficiency, reliability, and scalability. The infrastructure provides a robust environment for building enterprise-ready applications that are integral to business operations.

This SSRF vulnerability is present in the Component Build Service of the SAP NetWeaver Development Infrastructure. It arises due to inadequate validation of user-supplied input, allowing an attacker with access to the server to craft malicious requests. These requests can cause the server to interact with internal services, retrieve or manipulate data, or probe internal networks. Since the Component Build Service processes these requests, it inadvertently acts on behalf of the attacker, escalating the potential impact.

The exploitation of this SSRF vulnerability can lead to significant security breaches, including but not limited to, accessing and disclosing sensitive information, manipulating or deleting data, and potentially compromising the integrity and availability of the SAP NetWeaver Development Infrastructure. This could disrupt business operations, lead to financial losses, and damage the organization's reputation.

By leveraging the capabilities of S4E, organizations can significantly enhance their cybersecurity posture. Our platform offers comprehensive scanning tools that identify vulnerabilities like CVE-2021-33690, providing detailed reports and remediation guidance. Membership grants access to continuous monitoring and assessment services, ensuring that emerging threats are identified and mitigated promptly, safeguarding your digital assets against sophisticated cyber-attacks.

 

References

Solution Advice
  1. Immediately update to the latest version of SAP NetWeaver Development Infrastructure that addresses this SSRF vulnerability.
  2. Implement strict input validation to ensure only legitimate requests are processed by the Component Build Service.
  3. Configure network restrictions and firewall rules to limit the scope of accessible resources by the server, reducing the impact of potential SSRF exploits.
  4. Regularly review and apply security patches released by SAP and conduct periodic security assessments to identify and mitigate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-33690 scanner - Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure | S4E