VulnerabilityModified
CVE-2021-21468
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
MEDIUM 6.5EPSS 1.90%
Does this matter?
Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.
Description
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.90% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- sap/business warehouse
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/May/42Exploit, Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2986980Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476Vendor Advisory
- http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/May/42Exploit, Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2986980Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.