CVE-2021-21465

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:business_warehouse:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:782:*:*:*:*:*:*:*

History

03 Jun 2022, 13:18

Type Values Removed Values Added
References (MISC) https://launchpad.support.sap.com/#/notes/2986980 - (MISC) https://launchpad.support.sap.com/#/notes/2986980 - Permissions Required
References (MISC) http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html - (MISC) http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html - Exploit, Third Party Advisory, VDB Entry
References (FULLDISC) http://seclists.org/fulldisclosure/2022/May/42 - (FULLDISC) http://seclists.org/fulldisclosure/2022/May/42 - Exploit, Mailing List, Third Party Advisory

19 May 2022, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html -

19 May 2022, 00:15

Type Values Removed Values Added
References
  • (FULLDISC) http://seclists.org/fulldisclosure/2022/May/42 -

11 Feb 2021, 21:15

Type Values Removed Values Added
References
  • {'url': 'https://i7p.wdf.sap.corp/sap/support/notes/2986980', 'name': 'https://i7p.wdf.sap.corp/sap/support/notes/2986980', 'tags': ['Broken Link'], 'refsource': 'MISC'}
  • (MISC) https://launchpad.support.sap.com/#/notes/2986980 -

14 Jan 2021, 16:28

Type Values Removed Values Added
CWE CWE-89
References (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476 - (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476 - Vendor Advisory
References (MISC) https://i7p.wdf.sap.corp/sap/support/notes/2986980 - (MISC) https://i7p.wdf.sap.corp/sap/support/notes/2986980 - Broken Link
CPE cpe:2.3:a:sap:business_warehouse:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:782:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:753:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 9.9

12 Jan 2021, 15:38

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-12 15:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-21465

Mitre link : CVE-2021-21465

CVE.ORG link : CVE-2021-21465


JSON object : View

Products Affected

sap

  • business_warehouse
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')