Vulnerability record · CVE-2021-33690 · published 15 September 2021
CVE-2021-33690: SAP NetWeaver Development Infrastructure Build Service SSRF
Sap · Netweaver Development Infrastructure
The SAP NetWeaver Development Infrastructure Component Build Service is affected by a server-side request forgery flaw in versions 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50. An attacker with server access can send crafted queries that make the service act as a proxy, reaching internal systems and exposing sensitive data. The vendor notes impact depends on whether NWDI is exposed to the intranet or the internet.
Description
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS (9.9) and very high EPSS, but exploitation requires existing server access and no KEV or public exploit is recorded.
What it is
The SAP NetWeaver Development Infrastructure Component Build Service is affected by a server-side request forgery flaw in versions 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50. An attacker with server access can send crafted queries that make the service act as a proxy, reaching internal systems and exposing sensitive data. The vendor notes impact depends on whether NWDI is exposed to the intranet or the internet.
Impact
An attacker can use the build service to pivot requests into internal networks, potentially compromising sensitive data on the server and degrading its availability. The CVSS vector reflects worst-case internet exposure with high confidentiality, integrity and availability impact.
Attack surface
Reached over the network via crafted queries to the Component Build Service; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). The description states the attacker must already have access to the server.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is recorded in the references. EPSS is high at roughly 0.69 (99th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the SAP patch referenced in SAP Note 3072955 and the vendor advisory wiki page.
- Restrict network access to the NWDI Component Build Service, especially from the internet, and place it behind internal segmentation.
- Enforce least privilege on accounts that can reach the build service and remove unnecessary server access.
- Monitor and restrict outbound requests from the NWDI host to internal-only destinations.
- Review NWDI exposure to confirm whether it runs on the intranet or internet and adjust controls accordingly.
Detection
- Monitor NWDI Component Build Service logs for crafted or anomalous query patterns indicative of proxy abuse.
- Alert on outbound connections from the NWDI host to internal addresses or unexpected external endpoints.
- Baseline normal build service request destinations and flag deviations.
- Correlate server access events with subsequent SSRF-like request activity from the build service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://launchpad.support.sap.com/#/notes/3072955 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806 | PatchVendor Advisory |
| https://launchpad.support.sap.com/#/notes/3072955 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806 | PatchVendor Advisory |
Track CVE-2021-33690 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33690), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.