cbcvebase.
CVE-2023-0016
published 2023-01-10

CVE-2023-0016: SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection…

PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.62%
45.4th percentile
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.

Affected

4 ranges
VendorProductVersion rangeFixed in
sapbusiness_planning_and_consolidation
sapbusiness_planning_and_consolidation
sapsap_bpc_ms_10.0
sapsap_bpc_ms_10.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.