CVE-2021-21468 PUBLISHED CVSS 6.5 MEDIUM

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

EPSS 0.42% · 61.5th percentile

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.42%
61.5th percentile

Affected Products

VendorProductVersions
SAP SESAP Business Warehouse< 710, < 711, < 730
sapbusiness_warehouse710, 740, 750

Timeline

References

Open in Interactive Console →