CVE-2021-21465 PUBLISHED CVSS 9.899999618530273 CRITICAL

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

EPSS 1.43% · 80.5th percentile

Risk Scores

CVSS v3.0
9.899999618530273
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
1.43%
80.5th percentile

Affected Products

VendorProductVersions
SAP SESAP Business Warehouse< 710, < 711, < 730
sapbusiness_warehouse710, 711, 730

Timeline

References

Open in Interactive Console →