VYPR
Critical severity9.9NVD Advisory· Published Jan 10, 2023· Updated Jun 17, 2026

CVE-2023-0016

CVE-2023-0016

Description

SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.

Affected products

4
  • cpe:2.3:a:sap:business_planning_and_consolidation:800:*:*:*:*:microsoft:*:*+ 1 more
    • cpe:2.3:a:sap:business_planning_and_consolidation:800:*:*:*:*:microsoft:*:*
    • cpe:2.3:a:sap:business_planning_and_consolidation:810:*:*:*:*:microsoft:*:*
  • SAP/BPC MSllm-create
    Range: 810
  • SAP/SAP BPC MS 10.0v5
    Range: 800

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.