CVE-2021-21467 PUBLISHED CVSS 4.300000190734863 MEDIUM

SAP Banking Services (Generic Market Data) 400, 450, and 500 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business Partner Generic Market Data (GMD), due to improper authorization check.

EPSS 0.10% · 28.5th percentile

Risk Scores

CVSS v3.0
4.300000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.10%
28.5th percentile

Affected Products

VendorProductVersions
SAP SESAP Banking Services (Generic Market Data)< 450, < 500, *
sapbanking_services

Timeline

References

Open in Interactive Console →