CVE-2021-38176: SAP Landscape Transformation

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.

Affected products

  • SAP Landscape Transformation: version 2.0 only
  • SAP Landscape Transformation Replication Server: version 1.0 only; version 2.0 only; version 3.0 only
  • SAP s/4hana: version 1511 only; version 1610 only; version 1709 only; version 1809 only; version 1909 only; version 2020 only; …
  • SAP Test Data Migration Server: version 4.0 only

Published 2021-09-14. Last modified 2026-06-17.