High severity7.5NVD Advisory· Published Jul 14, 2021· Updated Jun 17, 2026
CVE-2021-33670
CVE-2021-33670
Description
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:sap:netweaver_application_server_java:7.10:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sap:netweaver_application_server_java:7.10:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.11:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.20:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:*
- Range: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
- Range: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
- SAP SE/SAP NetWeaver AS for Java (Http Service)v5Range: < 7.10
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/166965/SAP-NetWeaver-Java-Denial-Of-Service.htmlnvdPatchThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2022/May/4nvdMailing ListPatchThird Party Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.