Critical severity9.9NVD Advisory· Published Jan 10, 2023· Updated Jun 17, 2026
CVE-2023-0016
CVE-2023-0016
Description
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.
Affected products
4cpe:2.3:a:sap:business_planning_and_consolidation:800:*:*:*:*:microsoft:*:*+ 1 more
- cpe:2.3:a:sap:business_planning_and_consolidation:800:*:*:*:*:microsoft:*:*
- cpe:2.3:a:sap:business_planning_and_consolidation:810:*:*:*:*:microsoft:*:*
- SAP/SAP BPC MS 10.0v5Range: 800
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.