Skip to main content

Insufficient Logging

CVE-2021-33689

Severity Medium
Score 4.3/10

Summary

When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-778 - Insufficient Logging

When a security-critical event occurs, the software either does not record the event or omits important details about the event when logging it.

References

Advisory Timeline

  • Published