← Vulnerability feed

Vulnerability record · CVE-2021-33690 · published 15 September 2021

CVE-2021-33690: SAP NetWeaver Development Infrastructure Build Service SSRF

Sap · Netweaver Development Infrastructure

The SAP NetWeaver Development Infrastructure Component Build Service is affected by a server-side request forgery flaw in versions 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50. An attacker with server access can send crafted queries that make the service act as a proxy, reaching internal systems and exposing sensitive data. The vendor notes impact depends on whether NWDI is exposed to the intranet or the internet.

9.9 CVSS 3.1 Critical EPSS 69% · top 0.7% CWE-918 · Server-side request forgery (SSRF)
9.9CVSS 3.1 base score, v2 6.5
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCritical CVSS (9.9) and very high EPSS, but exploitation requires existing server access and no KEV or public exploit is recorded.

What it is

The SAP NetWeaver Development Infrastructure Component Build Service is affected by a server-side request forgery flaw in versions 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50. An attacker with server access can send crafted queries that make the service act as a proxy, reaching internal systems and exposing sensitive data. The vendor notes impact depends on whether NWDI is exposed to the intranet or the internet.

Impact

An attacker can use the build service to pivot requests into internal networks, potentially compromising sensitive data on the server and degrading its availability. The CVSS vector reflects worst-case internet exposure with high confidentiality, integrity and availability impact.

Attack surface

Reached over the network via crafted queries to the Component Build Service; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). The description states the attacker must already have access to the server.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is recorded in the references. EPSS is high at roughly 0.69 (99th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the SAP patch referenced in SAP Note 3072955 and the vendor advisory wiki page.
  • Restrict network access to the NWDI Component Build Service, especially from the internet, and place it behind internal segmentation.
  • Enforce least privilege on accounts that can reach the build service and remove unnecessary server access.
  • Monitor and restrict outbound requests from the NWDI host to internal-only destinations.
  • Review NWDI exposure to confirm whether it runs on the intranet or internet and adjust controls accordingly.

Detection

  • Monitor NWDI Component Build Service logs for crafted or anomalous query patterns indicative of proxy abuse.
  • Alert on outbound connections from the NWDI host to internal addresses or unexpected external endpoints.
  • Baseline normal build service request destinations and flag deviations.
  • Correlate server access events with subsequent SSRF-like request activity from the build service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33690 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2013-6820Sap netweaver development infrastructure vulnerabilityUnrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers to execute arbitrary code by up…EPSS 3.6%6.1CVE-2022-29618Sap netweaver development infrastructure cross-site scripting vulnerabilityDue to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an …EPSS 1.1%6.1CVE-2021-33691Sap netweaver development infrastructure cross-site scripting vulnerabilityNWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) v…EPSS 0.64%10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.3CVE-2026-64849MLflow unauthenticated webhook test endpoint SSRF via redirectMLflow before 3.15.0 validates the webhook URL only on the original request, while the delivery code follows redirects and re-resolves the hostname w…KEVEPSS 9.8%analysed10.0CVE-2026-15409SonicWall SMA1000 Work Place SSRF allows unauthenticated requestsThe SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests …KEVEPSS 6.8%analysed8.6CVE-2026-20230Cisco Unified CM SSRF enables file write and root escalationCisco Unified Communications Manager and Unified CM SME fail to properly validate input for specific HTTP requests, allowing server-side request forg…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2021-33690), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.