Back to overview

CVE-2021-21465

CRITICAL
9.9
CVSS 3.0
Description
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

Metadata

CVE ID
CVE-2021-21465
State
PUBLISHED
Assigner
sap
Reserved
2020-12-30 00:00 UTC
Published
2021-01-12 14:40 UTC
Last updated
2024-08-03 18:16 UTC
Vendor / Product
SAP SE / SAP Business Warehouse
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
SAP SE SAP Business Warehouse < 710, < 711, < 730, < 731 …
Weakness (CWE)
CWESourceDescription
cna SQL Injection
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview