SQL Injection Vulnerability in SAP BW Database Interface
CVE-2021-21465
9.9CRITICAL
Summary
A vulnerability in the SAP BW Database Interface permits an attacker with low privileges to execute arbitrary SQL queries against the backend database. This occurs due to inadequate validation of untrusted input, enabling the attacker to inject malicious SQL commands. If exploited, this vulnerability can compromise the integrity and confidentiality of the data stored in the SAP system, leading to potential unauthorized access and manipulation of sensitive information.
Affected Version(s)
SAP Business Warehouse < 710 < 710
SAP Business Warehouse < 711 < 711
SAP Business Warehouse < 730 < 730
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved