← Vulnerability feed

Vulnerability record · CVE-2021-38163 · published 14 September 2021

CVE-2021-38163: SAP NetWeaver Visual Composer unrestricted file upload leads to RCE

Sap · Netweaver

SAP NetWeaver Visual Composer 7.0 RT (versions 7.30, 7.31, 7.40, 7.50) allows an authenticated non-administrative user to upload a malicious file over the network and trigger its processing. The flaw is classified as CWE-22 path traversal and results in operating system command execution with the privileges of the Java Server process.

8.8 CVSS 3.1 High CISA KEV since 9 Jun 2022 EPSS 36% · top 1.6% CWE-22 · Path traversal
8.8CVSS 3.1 base score, v2 9.0
36%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 with network reachability, low complexity, and authenticated non-admin access, plus confirmed KEV listing and high EPSS percentile, make this a high-priority remediation target.

What it is

SAP NetWeaver Visual Composer 7.0 RT (versions 7.30, 7.31, 7.40, 7.50) allows an authenticated non-administrative user to upload a malicious file over the network and trigger its processing. The flaw is classified as CWE-22 path traversal and results in operating system command execution with the privileges of the Java Server process.

Impact

An attacker gains OS command execution as the Java Server process, enabling reading or modification of any server information or shutting the server down to cause unavailability.

Attack surface

Reachable over the network via the Visual Composer upload functionality; the attacker must be authenticated as a non-administrative user, and no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N).

Exploitation

CVE-2021-38163 is listed in CISA KEV (added 2022-06-09, due 2022-06-30) and has an EPSS 30-day probability of 0.36018 (98.4th percentile), indicating observed exploitation activity; CISA KEV notes no known ransomware campaign use.

What to do

  • Apply the SAP security note 3084487 updates for NetWeaver Visual Composer 7.0 RT (7.30, 7.31, 7.40, 7.50) as directed by the vendor.
  • Restrict network access to Visual Composer upload endpoints to trusted users and networks.
  • Review and minimize non-administrative accounts with access to Visual Composer functionality.
  • Monitor and alert on unexpected file uploads and process execution originating from the Java Server process.

Detection

  • Monitor for file uploads to Visual Composer endpoints followed by unexpected child processes spawned by the Java Server process.
  • Alert on path traversal patterns in uploaded filenames or multipart requests targeting NetWeaver.
  • Audit non-administrative user activity involving Visual Composer upload and processing functions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-38163 to the Known Exploited Vulnerabilities catalog on 9 June 2022 as "SAP NetWeaver Unrestricted File Upload Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 30 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38163 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader unauthenticated file uploadThe SAP NetWeaver Visual Composer Metadata Uploader lacks proper authorization checks, letting an unauthenticated agent upload executable binaries to…KEVEPSS 99%analysed9.1CVE-2025-42999SAP NetWeaver Visual Composer Metadata Uploader deserialization flawSAP NetWeaver Visual Composer Metadata Uploader deserializes untrusted content uploaded by a privileged user, allowing malicious payloads to execute …KEVEPSS 14%analysed10.0CVE-2013-6822Sap netweaver vulnerabilityGRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue.EPSS 2.2%9.8CVE-2011-1517Sap netweaver vulnerabilitySAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafte…EPSS 4.2%9.8CVE-2013-1592Sap netweaver classic buffer overflow vulnerabilityA Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Serv…EPSS 24%9.8CVE-2015-7241Sap netweaver xml external entity (xxe) vulnerabilityXML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.EPSS 13%9.8CVE-2016-10311Sap netweaver memory buffer overflow vulnerabilityStack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to t…EPSS 2.2%9.3CVE-2012-2611Sap netweaver improper input validation vulnerabilityThe DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EH…EPSS 44%

Source: NIST National Vulnerability Database (record CVE-2021-38163), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.