CVE-2021-21468: Medium severity sap business warehouse vulnerability
Published Jan 12, 2021
·Updated
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
Affected Software
12 affected components
SAP Business Warehouse=710
SAP Business Warehouse=711
SAP Business Warehouse=730
SAP Business Warehouse=731
SAP Business Warehouse=740
SAP Business Warehouse=750
SAP Business Warehouse=751
SAP Business Warehouse=752
SAP Business Warehouse=753
SAP Business Warehouse=754
SAP Business Warehouse=755
SAP Business Warehouse=782
Event History
Jan 12, 2021
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-21468.
2
What is the severity level of CVE-2021-21468?
The severity level of CVE-2021-21468 is medium.
3
What is the description of CVE-2021-21468?
CVE-2021-21468 is a vulnerability in the BW Database Interface that allows an authenticated user to escalate privileges and read out any database table.
4
Which software versions are affected by CVE-2021-21468?
SAP Business Warehouse versions 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, and 782 are affected by CVE-2021-21468.
5
How can I fix CVE-2021-21468?
To fix CVE-2021-21468, apply the necessary security patches provided by SAP.