CVE-2021-33693
CVE-2021-33693 is a medium-severity vulnerability in Sap Cloud Connector with a CVSS 3.x base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Medium (CVSS 3.x base score 6.8)
- CVSS v2: 7.7
- EPSS exploit prediction: 1% (43rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Sap Cloud Connector
- Published:
- Last modified:
Description
SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution.
Frequently asked questions
- What is CVE-2021-33693?
- SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution.
- How severe is CVE-2021-33693?
- CVE-2021-33693 has a CVSS 3.x base score of 6.8, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2021-33693 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (43rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-33693?
- CVE-2021-33693 affects Sap Cloud Connector. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-33693?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-33693 published?
- CVE-2021-33693 was published on 2021-09-15 and last updated on 2026-06-17.
References
- https://launchpad.support.sap.com/#/notes/3058553
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806
Affected products (1)
- cpe:2.3:a:sap:cloud_connector:2.0:*:*:*:*:*:*:*
More vulnerabilities in Sap Cloud Connector
- CVE-2019-0247 — Critical (CVSS 9.8): SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application.…
- CVE-2019-0246 — Critical (CVSS 9.8): SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require…
- CVE-2021-33695 — Critical (CVSS 9.1): Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient…
- CVE-2021-33692 — High (CVSS 7.5): SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject…
- CVE-2024-25642 — High (CVSS 7.4): Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine…
- CVE-2021-33694 — Medium (CVSS 4.8): SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with…
All CVEs affecting Sap Cloud Connector →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…