Unrated severityNVD Advisory· Published Jan 12, 2021· Updated Aug 3, 2024
CVE-2021-21465
CVE-2021-21465
Description
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- SAP SE/SAP Business Warehousev5Range: < 710
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2022/May/42mitremailing-listx_refsource_FULLDISC
- launchpad.support.sap.commitrex_refsource_MISC
- wiki.scn.sap.com/wiki/pages/viewpage.actionmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.