CVE-2021-38176 is an improper input sanitization vulnerability affecting SAP Landscape Transformation, S/4HANA, and Test Data Migration Server products. An authenticated user with specific privileges can remotely inject ABAP code or manipulate queries to gain full control over the backend database, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS score of 8.8 (High), it has a low attack complexity and requires no user interaction. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it was addressed in SAP's September 2021 security updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:sap:landscape_transformation:2.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:sap:landscape_transformation_replication_server:1.0:*:*:*:*:s\/4hana:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:sap:landscape_transformation_replication_server:2.0:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:sap:landscape_transformation_replication_server:3.0:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:a:sap:s\/4hana:1511:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.