Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21466


SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.


Published

2021-01-12T15:15:15.953

Last Modified

2024-11-21T05:48:25.767

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap business_warehouse 700 Yes
Application sap business_warehouse 701 Yes
Application sap business_warehouse 702 Yes
Application sap business_warehouse 711 Yes
Application sap business_warehouse 730 Yes
Application sap business_warehouse 731 Yes
Application sap business_warehouse 740 Yes
Application sap business_warehouse 750 Yes
Application sap business_warehouse 782 Yes
Application sap bw\/4hana 100 Yes
Application sap bw\/4hana 200 Yes

References