SQL Injection Vulnerability in SAP BW Database Interface
CVE-2021-21465

9.9CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 January 2021

Summary

A vulnerability in the SAP BW Database Interface permits an attacker with low privileges to execute arbitrary SQL queries against the backend database. This occurs due to inadequate validation of untrusted input, enabling the attacker to inject malicious SQL commands. If exploited, this vulnerability can compromise the integrity and confidentiality of the data stored in the SAP system, leading to potential unauthorized access and manipulation of sensitive information.

Affected Version(s)

SAP Business Warehouse < 710 < 710

SAP Business Warehouse < 711 < 711

SAP Business Warehouse < 730 < 730

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.