Vulnerability record · CVE-2021-27635 · published 9 June 2021
CVE-2021-27635: Sap netweaver application server for java xml external entity (xxe) vulnerability
Sap · Netweaver Application Server For Java
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.
Description
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164592/SAP-JAVA-NetWeaver-System-Connections-XML-Injection.html | PatchThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Oct/28 | Mailing ListPatchThird Party Advisory |
| https://launchpad.support.sap.com/#/notes/3053066 | Permissions RequiredVendor Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 | Vendor Advisory |
| http://packetstormsecurity.com/files/164592/SAP-JAVA-NetWeaver-System-Connections-XML-Injection.html | PatchThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Oct/28 | Mailing ListPatchThird Party Advisory |
| https://launchpad.support.sap.com/#/notes/3053066 | Permissions RequiredVendor Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 | Vendor Advisory |
Track CVE-2021-27635 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27635), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.