6.5

CVE-2021-21468

Exploit
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Business Warehouse Version 710
SAP ≫ Business Warehouse Version 711
SAP ≫ Business Warehouse Version 730
SAP ≫ Business Warehouse Version 731
SAP ≫ Business Warehouse Version 740
SAP ≫ Business Warehouse Version 750
SAP ≫ Business Warehouse Version 751
SAP ≫ Business Warehouse Version 752
SAP ≫ Business Warehouse Version 753
SAP ≫ Business Warehouse Version 754
SAP ≫ Business Warehouse Version 755
SAP ≫ Business Warehouse Version 782
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.9% 0.769
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
SAP 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2022/May/42
Third Party Advisory
Exploit
Mailing List
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476
Vendor Advisory
https://launchpad.support.sap.com/#/notes/2986980
Vendor Advisory
Permissions Required