Vulnerability record · CVE-2021-38163 · published 14 September 2021
CVE-2021-38163: SAP NetWeaver Visual Composer unrestricted file upload leads to RCE
Sap · Netweaver
SAP NetWeaver Visual Composer 7.0 RT (versions 7.30, 7.31, 7.40, 7.50) allows an authenticated non-administrative user to upload a malicious file over the network and trigger its processing. The flaw is classified as CWE-22 path traversal and results in operating system command execution with the privileges of the Java Server process.
Description
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, low complexity, and authenticated non-admin access, plus confirmed KEV listing and high EPSS percentile, make this a high-priority remediation target.
What it is
SAP NetWeaver Visual Composer 7.0 RT (versions 7.30, 7.31, 7.40, 7.50) allows an authenticated non-administrative user to upload a malicious file over the network and trigger its processing. The flaw is classified as CWE-22 path traversal and results in operating system command execution with the privileges of the Java Server process.
Impact
An attacker gains OS command execution as the Java Server process, enabling reading or modification of any server information or shutting the server down to cause unavailability.
Attack surface
Reachable over the network via the Visual Composer upload functionality; the attacker must be authenticated as a non-administrative user, and no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N).
Exploitation
CVE-2021-38163 is listed in CISA KEV (added 2022-06-09, due 2022-06-30) and has an EPSS 30-day probability of 0.36018 (98.4th percentile), indicating observed exploitation activity; CISA KEV notes no known ransomware campaign use.
What to do
- Apply the SAP security note 3084487 updates for NetWeaver Visual Composer 7.0 RT (7.30, 7.31, 7.40, 7.50) as directed by the vendor.
- Restrict network access to Visual Composer upload endpoints to trusted users and networks.
- Review and minimize non-administrative accounts with access to Visual Composer functionality.
- Monitor and alert on unexpected file uploads and process execution originating from the Java Server process.
Detection
- Monitor for file uploads to Visual Composer endpoints followed by unexpected child processes spawned by the Java Server process.
- Alert on path traversal patterns in uploaded filenames or multipart requests targeting NetWeaver.
- Audit non-administrative user activity involving Visual Composer upload and processing functions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-38163 to the Known Exploited Vulnerabilities catalog on 9 June 2022 as "SAP NetWeaver Unrestricted File Upload Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 30 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://launchpad.support.sap.com/#/notes/3084487 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 | Broken LinkVendor Advisory |
| https://launchpad.support.sap.com/#/notes/3084487 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38163 | US Government Resource |
Track CVE-2021-38163 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38163), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.