cbcvebase.
CVE-2021-21468
published 2021-01-12

CVE-2021-21468: The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

Affected

24 ranges
VendorProductVersion rangeFixed in
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sapbusiness_warehouse
sap_sesap_business_warehouse< 710710
sap_sesap_business_warehouse< 711711
sap_sesap_business_warehouse< 730730
sap_sesap_business_warehouse< 731731
sap_sesap_business_warehouse< 740740
sap_sesap_business_warehouse< 750750
sap_sesap_business_warehouse< 751751
sap_sesap_business_warehouse< 752752
sap_sesap_business_warehouse< 753753
sap_sesap_business_warehouse< 754754
sap_sesap_business_warehouse< 755755
sap_sesap_business_warehouse< 782782