SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
Use CWE-22, Sap vendor hub and Netweaver product page to widen CVE-2021-38163 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-31324, CVE-2025-42999 and CVE-2023-36922 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.