CVE-2021-21465: SQL Injection
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-21465.
What is the severity of CVE-2021-21465?
The severity of CVE-2021-21465 is critical with a score of 9.9.
Which software is affected by CVE-2021-21465?
The SAP Business Warehouse versions 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, and 782 are affected by CVE-2021-21465.
What is the impact of CVE-2021-21465?
CVE-2021-21465 allows an attacker with low privileges to execute crafted database queries, leading to SQL injection vulnerabilities and exposing the backend database.
Are there any references for CVE-2021-21465?
Yes, you can find more information about CVE-2021-21465 at the following references: [link 1](http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html), [link 2](http://seclists.org/fulldisclosure/2022/May/42), [link 3](https://launchpad.support.sap.com/#/notes/2986980).