CVE-2021-33683 is a medium-severity HTTP Request Smuggling vulnerability affecting SAP Web Dispatcher and Internet Communication Manager (ICM) across numerous kernel versions. It arises from improper handling of invalid Transfer-Encoding HTTP headers, allowing an attacker to manipulate how requests are processed. Exploitation could bypass web application firewalls and divert sensitive data like session credentials. While the CVSS score is 4.3, indicating a low impact on integrity and no impact on confidentiality or availability, its FAUCET Risk Score is 9/100. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.8_kernel_7.21CPE matchmatch criteria | cpe:2.3:a:sap:web_dispatcher:7.8_kernel_7.21:*:*:*:*:*:*:* | ||
7.21extCPE matchmatch criteria | cpe:2.3:a:sap:web_dispatcher:7.21ext:*:*:*:*:*:*:* | ||
7.22CPE matchmatch criteria | cpe:2.3:a:sap:web_dispatcher:7.22:*:*:*:*:*:*:* | ||
7.22extCPE matchmatch criteria | cpe:2.3:a:sap:web_dispatcher:7.22ext:*:*:*:*:*:*:* | ||
7.49CPE matchmatch criteria | cpe:2.3:a:sap:web_dispatcher:7.49:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.