Critical severity9.9NVD Advisory· Published Jan 12, 2021· Updated Jun 17, 2026
CVE-2021-21465
CVE-2021-21465
Description
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- SAP SE/SAP Business Warehousev5Range: < 710
cpe:2.3:a:sap:business_warehouse:710:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:sap:business_warehouse:710:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:711:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:730:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:750:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:751:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:752:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:754:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:755:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_warehouse:782:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2022/May/42nvdExploitMailing ListThird Party Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.