PT-2021-14534 · Sap · Sap Business Warehouse+1

Alexander Meier

+1

·

Published

2021-01-12

·

Updated

2022-10-01

·

CVE-2021-21466

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Business Warehouse versions 700 through 750, 782 SAP BW/4HANA versions 100 through 200
Description The issue allows a low-privileged attacker to inject code using a remote-enabled function module over the network. This can lead to the creation of a malicious ABAP report, which can be used to access sensitive data, inject malicious UPDATE statements that could impact the operating system, or disrupt the functionality of the SAP system, potentially leading to a Denial of Service.
Recommendations For SAP Business Warehouse versions 700 through 750, 782, update to a version that includes the fix for this issue. For SAP BW/4HANA versions 100 through 200, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-21466

Affected Products

Sap Bw/4Hana
Sap Business Warehouse