Back to overview

CVE-2021-21466

CRITICAL
9.9
CVSS 3.0
Description
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.

Metadata

CVE ID
CVE-2021-21466
State
PUBLISHED
Assigner
sap
Reserved
2020-12-30 00:00 UTC
Published
2021-01-12 14:42 UTC
Last updated
2024-08-03 18:16 UTC
Vendor / Product
SAP SE / SAP Business Warehouse
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
SAP SE SAP Business Warehouse < 700, < 701, < 702, < 711 …
SAP SE SAP BW/4HANA < 100, < 200
Weakness (CWE)
CWESourceDescription
cna Code Injection
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview