{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"SAP SuccessFactors Mobile Application (pour les \u00e9quipements Android), Versions - <2108","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP NetWeaver AS ABAP et ABAP Platform, Versions - 740, 750, 751, 752, 753, 754, 755","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP BusinessObjects Business Intelligence Platform (Crystal Reports), Versions - 420, 430","product":{"name":"SAP BusinessObjects Business Intelligence","vendor":{"name":"SAP","scada":false}}},{"description":"SAP Business Client, Version \u2013 6.5","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP BusinessObjects Analysis, (\u00e9dition pour OLAP), Versions - 420, 430","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP Environmental Compliance, Version - 3.0","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP NetWeaver Application Server pour ABAP (SAP Cloud Print Manager et SAPSprint), Versions - 7.70, 7.70 PI, 7.70BYD","product":{"name":"NetWeaver Application Server pour ABAP","vendor":{"name":"SAP","scada":false}}},{"description":"SAP Business One, Version - 10.0","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP NetWeaver, Versions - 700, 701, 702, 730","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP NetWeaver AS ABAP et ABAP Platform, Versions - 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAPUI5, Versions - 750, 753, 754","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP NetWeaver AS ABAP et ABAP Platform, Versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}},{"description":"SAP NetWeaver AS ABAP and ABAP Platform, Versions - 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756","product":{"name":"N/A","vendor":{"name":"SAP","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2021-40498","url":"https://www.cve.org/CVERecord?id=CVE-2021-40498"},{"name":"CVE-2021-38180","url":"https://www.cve.org/CVERecord?id=CVE-2021-38180"},{"name":"CVE-2020-10683","url":"https://www.cve.org/CVERecord?id=CVE-2020-10683"},{"name":"CVE-2021-40500","url":"https://www.cve.org/CVERecord?id=CVE-2021-40500"},{"name":"CVE-2021-38179","url":"https://www.cve.org/CVERecord?id=CVE-2021-38179"},{"name":"CVE-2021-23926","url":"https://www.cve.org/CVERecord?id=CVE-2021-23926"},{"name":"CVE-2021-38183","url":"https://www.cve.org/CVERecord?id=CVE-2021-38183"},{"name":"CVE-2021-38181","url":"https://www.cve.org/CVERecord?id=CVE-2021-38181"},{"name":"CVE-2021-40496","url":"https://www.cve.org/CVERecord?id=CVE-2021-40496"},{"name":"CVE-2021-40497","url":"https://www.cve.org/CVERecord?id=CVE-2021-40497"},{"name":"CVE-2021-40495","url":"https://www.cve.org/CVERecord?id=CVE-2021-40495"},{"name":"CVE-2021-38178","url":"https://www.cve.org/CVERecord?id=CVE-2021-38178"},{"name":"CVE-2021-40499","url":"https://www.cve.org/CVERecord?id=CVE-2021-40499"},{"name":"CVE-2020-11023","url":"https://www.cve.org/CVERecord?id=CVE-2020-11023"}],"links":[],"reference":"CERTFR-2021-AVI-770","revisions":[{"description":"Version initiale","revision_date":"2021-10-12T00:00:00.000000"}],"risks":[{"description":"Injection de code indirecte \u00e0 distance (XSS)"},{"description":"D\u00e9ni de service"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits SAP.\nCertaines d'entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni\nde service, un contournement de la politique de s\u00e9curit\u00e9 et une atteinte\n\u00e0 la confidentialit\u00e9 des donn\u00e9es.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans les produits SAP","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SAP 587169983 du 12 octobre 2021","url":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983"}]}
