6.5

CVE-2021-21468

Exploit

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

Data is provided by the National Vulnerability Database (NVD)
SAPBusiness Warehouse Version710
SAPBusiness Warehouse Version711
SAPBusiness Warehouse Version730
SAPBusiness Warehouse Version731
SAPBusiness Warehouse Version740
SAPBusiness Warehouse Version750
SAPBusiness Warehouse Version751
SAPBusiness Warehouse Version752
SAPBusiness Warehouse Version753
SAPBusiness Warehouse Version754
SAPBusiness Warehouse Version755
SAPBusiness Warehouse Version782
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.42% 0.611
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
cna@sap.com 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.