2 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en Data Basis (BW-WHM-DBA) en SAP NetWeaver Business Warehouse permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de vectores no especificados. • http://blog.onapsis.com/analyzing-sap-security-notes-october-2014-edition http://service.sap.com/sap/support/notes/0001965819 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 3.5EPSS: 0%CPEs: 1EXPL: 0

The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors. El componente SAP Netweaver Business Warehouse no restringe debidamente el acceso a las funciones en el grupo de funciones BW-SYS-DB-DB4, lo que permite a usuarios remotos autenticados obtener información sensible a través de vectores no especificados. • http://packetstormsecurity.com/files/127671/SAP-Netweaver-Business-Warehouse-Missing-Authorization.html http://scn.sap.com/docs/DOC-8218 http://seclists.org/fulldisclosure/2014/Jul/154 http://secunia.com/advisories/59635 http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-026 http://www.securityfocus.com/bid/68955 https://exchange.xforce.ibmcloud.com/vulnerabilities/94921 https://service.sap.com/sap/support/notes/1974016 • CWE-264: Permissions, Privileges, and Access Controls •