cbcvebase.
CVE-2021-21465
published 2021-01-12

CVE-2021-21465: The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can…

critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

Affected

24 ranges
VendorProductVersion rangeFixed in
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sap_sesap_business_warehouse< 710710
sap_sesap_business_warehouse< 711711
sap_sesap_business_warehouse< 730730
sap_sesap_business_warehouse< 731731
sap_sesap_business_warehouse< 740740
sap_sesap_business_warehouse< 750750
sap_sesap_business_warehouse< 751751
sap_sesap_business_warehouse< 752752
sap_sesap_business_warehouse< 753753
sap_sesap_business_warehouse< 754754
sap_sesap_business_warehouse< 755755
sap_sesap_business_warehouse< 782782