PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-38163 SAP CVE debrief

CVE-2021-38163 is a SAP NetWeaver unrestricted file upload vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-06-09, which means it is treated as a known exploited issue and should be prioritized for remediation. The supplied record directs defenders to apply updates per vendor instructions.

Vendor
SAP
Product
NetWeaver
CVSS
CRITICAL 9.9
CISA KEV
Listed
Original CVE published
2022-06-09
Original CVE updated
2022-06-09
Advisory published
2022-06-09
Advisory updated
2022-06-09

Who should care

SAP NetWeaver administrators, SAP platform owners, security teams, and managed service providers responsible for SAP environments should prioritize this CVE. Any internet-facing or widely reachable SAP NetWeaver deployment should be reviewed immediately.

Technical summary

The available source material identifies CVE-2021-38163 as an unrestricted file upload vulnerability in SAP NetWeaver. The corpus does not include affected versions or the full exploitation chain, but CISA’s KEV listing confirms known exploitation and recommends applying updates per vendor instructions.

Defensive priority

High

Recommended defensive actions

  • Inventory SAP NetWeaver deployments and identify any systems that may be affected.
  • Apply SAP vendor-recommended updates and remediation steps as soon as possible.
  • Restrict access to SAP NetWeaver systems, especially any internet-facing instances.
  • Review logs and file-upload related activity for suspicious uploads or unexpected file changes.
  • Track the CISA KEV due date of 2022-06-30 and confirm remediation is complete.

Evidence notes

The source corpus includes the CISA KEV record for CVE-2021-38163, which names SAP NetWeaver as the affected product, labels the issue as an unrestricted file upload vulnerability, and lists dateAdded 2022-06-09 with dueDate 2022-06-30. The record’s note points to the NVD detail page and states: “Apply updates per vendor instructions.” No CVSS score or affected-version details were provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-38163 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-38163

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-38163 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-38163

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.