PT-2021-14536 · Unknown · Bw Database Interface

Alexander Meier

+1

·

Published

2021-01-12

·

Updated

2022-10-01

·

CVE-2021-21468

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BW Database Interface (affected versions not specified)
Description The issue is related to the BW Database Interface not performing necessary authorization checks for an authenticated user. This results in an escalation of privileges, allowing the user to read out any database table.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-21468

Affected Products

Bw Database Interface