8.8

CVE-2021-21466

Exploit
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Business Warehouse Version 700
SAP ≫ Business Warehouse Version 701
SAP ≫ Business Warehouse Version 702
SAP ≫ Business Warehouse Version 711
SAP ≫ Business Warehouse Version 730
SAP ≫ Business Warehouse Version 731
SAP ≫ Business Warehouse Version 740
SAP ≫ Business Warehouse Version 750
SAP ≫ Business Warehouse Version 782
SAP ≫ Bw/4hana Version 100
SAP ≫ Bw/4hana Version 200
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.08% 0.86
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
SAP 9.9 3.1 6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2022/May/42
Third Party Advisory
Exploit
Mailing List
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476
Vendor Advisory
https://launchpad.support.sap.com/#/notes/2999854
Vendor Advisory
Permissions Required