← Back

CVE-2021-21468

nvd nist
Published: Jan 12, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

Affected (12)

1 product
Business Warehouse
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 710
Version 711
Version 730
Version 731
Version 740
Version 750
Version 751
Version 752
Version 753
Version 754
Version 755
Version 782

References (8)

Source: cna@sap.com
ExploitMailing ListThird Party Advisory
Source: cna@sap.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.