VYPR
High severity7.5NVD Advisory· Published Apr 14, 2021· Updated Jun 17, 2026

CVE-2021-27608

CVE-2021-27608

Description

An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered. This could further lead to complete compromise of confidentiality, Integrity and Availability.

Affected products

3
  • cpe:2.3:a:sap:setup:9.0:*:*:*:*:*:*:*
  • SAP/SAPSetupllm-fuzzy
    Range: = 9.0
  • SAP SE/SAP Setupv5
    Range: < 9.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.