CVE-2021-27610
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

SAP NetWeaver ABAP Server and ABAP Platform (versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804) contains a critical authentication vulnerability (CVE-2021-27610) that was disclosed in February 2021. The vulnerability stems from inconsistent formatting of information about internal and external RFC users, which could lead to improper authentication (CVE Mitre).

Technical details

CVE-2021-27610 is an authentication bypass vulnerability in AS ABAP that allows adversaries to escalate privileges on affected systems. The vulnerability has been assigned a CVSS score of 9.0, indicating its critical severity. The core issue lies in the system's handling of RFC user information, which does not maintain consistent and distinguished formatting between internal and external users (CERT-EU).

Impact

The vulnerability enables attackers to establish their own communication with vulnerable systems, reuse leaked credentials, and impersonate user accounts. This can ultimately lead to a full system compromise, affecting the confidentiality, integrity, and availability of the SAP system (SOCRadar).

Mitigation and workarounds

SAP has addressed this vulnerability by releasing a patch through SAP Security Note 3007182. Organizations are strongly advised to implement the patch promptly. Additional recommended security measures include limiting network-wise access to vulnerable servers, enforcing encrypted server-to-server communications using HTTPS and SNC, and reducing authorization distributions to minimize potential risks (SOCRadar).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-42945MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesAug 12, 2025
CVE-2025-42956MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 08, 2025
CVE-2025-42981MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 08, 2025
CVE-2025-42969MEDIUM6.1
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 08, 2025
CVE-2025-42902MEDIUM5.3
  • SAP NetWeaver Application Server ABAPSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesOct 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management