VDB
CVE-2021-21466
CVE-2021-21466
PUBLISHED
CVSS 9.899999618530273 CRITICAL
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.
EPSS 0.70% · 72.4th percentile
Risk Scores
CVSS 3.0
9.899999618530273
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.70%
72.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP SE | SAP Business Warehouse | < 700, < 702, < 731 |
| sap | bw\/4hana | 100, 200 |
| sap | business_warehouse | 700, 701, 702 |
| SAP SE | SAP BW/4HANA | < 100, < 200 |
Exploit Intelligence
- http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html (nist-nvd)
- http://seclists.org/fulldisclosure/2022/May/42 (nist-nvd)
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476 (circl)
- https://launchpad.support.sap.com/#/notes/2999854 (circl)
Timeline
- Jan 12, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
- Jul 14, 2023 EPSS Score
References
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476 advisory
- https://launchpad.support.sap.com/#/notes/2999854 url
- 20220518 SEC Consult SA-20220518-0 :: Multiple Critical Vulnerabilities in SAP Application Server, ABAP and ABAP Platform (Different Software Components) mailing-list
- http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-21466 advisory
- https://i7p.wdf.sap.corp/sap/support/notes/2999854 url