← Back

CVE-2021-21465

nvd nist
Published: Jan 12, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: NVD

Description

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

Affected (12)

1 product
Business Warehouse
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 710
Version 711
Version 730
Version 731
Version 740
Version 750
Version 751
Version 752
Version 753
Version 754
Version 755
Version 782

References (8)

Source: cna@sap.com
ExploitMailing ListThird Party Advisory
Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.