SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21465

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database.

CRITICAL 9.9EPSS 3.67%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

CVSS 3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
3.67% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
sap/business warehouse
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.