cbcvebase.
CVE-2021-21466
published 2021-01-12

CVE-2021-21466: SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.

Affected

22 ranges
VendorProductVersion rangeFixed in
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbw_4hana
sapbw_4hana
sap_sesap_business_warehouse< 700700
sap_sesap_business_warehouse< 701701
sap_sesap_business_warehouse< 702702
sap_sesap_business_warehouse< 711711
sap_sesap_business_warehouse< 730730
sap_sesap_business_warehouse< 731731
sap_sesap_business_warehouse< 740740
sap_sesap_business_warehouse< 750750
sap_sesap_business_warehouse< 782782
sap_sesap_bw_4hana< 100100
sap_sesap_bw_4hana< 200200