CISA Known Exploited Vulnerability

CVE-2021-38163

SAP · NetWeaver

SAP NetWeaver Unrestricted File Upload Vulnerability

Date added
BOD 22-01 due date
CWE CWE-23
Ransomware Unknown

CISA description

SAP NetWeaver contains a vulnerability that allows unrestricted file upload.

Required action

Apply updates per vendor instructions.