CVE-2021-33690 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting multiple versions of the SAP NetWeaver Development Infrastructure Component Build Service. An authenticated attacker can exploit this flaw by sending crafted queries, enabling proxy attacks that could lead to complete compromise of sensitive data and impact system availability. With a CVSS score of 9.9 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk, especially when exposed to the internet. While no active exploitation or public Metasploit/ExploitDB modules are reported, Nuclei templates exist, and there is notable community discussion and media coverage surrounding this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.11CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_development_infrastructure:7.11:*:*:*:*:*:*:* | ||
7.20CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_development_infrastructure:7.20:*:*:*:*:*:*:* | ||
7.30CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_development_infrastructure:7.30:*:*:*:*:*:*:* | ||
7.31CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_development_infrastructure:7.31:*:*:*:*:*:*:* | ||
7.40CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_development_infrastructure:7.40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.