Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21468


The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.


Published

2021-01-12T15:15:16.093

Last Modified

2024-11-21T05:48:26.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap business_warehouse 710 Yes
Application sap business_warehouse 711 Yes
Application sap business_warehouse 730 Yes
Application sap business_warehouse 731 Yes
Application sap business_warehouse 740 Yes
Application sap business_warehouse 750 Yes
Application sap business_warehouse 751 Yes
Application sap business_warehouse 752 Yes
Application sap business_warehouse 753 Yes
Application sap business_warehouse 754 Yes
Application sap business_warehouse 755 Yes
Application sap business_warehouse 782 Yes

References