// For flags

CVE-2021-21465

SAP Application Server ABAP / ABAP Platform Code Injection / SQL Injection / Missing Authorization

Severity Score

9.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

La Interfaz de Base de Datos de BW permite a un atacante con pocos privilegios ejecutar cualquier consulta de la base de datos diseñada, exponiendo la base de datos del backend. Un atacante puede incluir sus propios comandos SQL que la base de datos ejecutará sin sanear apropiadamente los datos no confiables, conllevando a una vulnerabilidad de inyección SQL que puede comprometer por completo el sistema SAP afectado

The SAP application server ABAP and ABAP Platform are susceptible to code injection, SQL injection, and missing authorization vulnerabilities. Multiple SAP products are affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-30 CVE Reserved
  • 2021-01-12 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-09-29 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
710
Search vendor "Sap" for product "Business Warehouse" and version "710"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
711
Search vendor "Sap" for product "Business Warehouse" and version "711"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
730
Search vendor "Sap" for product "Business Warehouse" and version "730"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
731
Search vendor "Sap" for product "Business Warehouse" and version "731"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
740
Search vendor "Sap" for product "Business Warehouse" and version "740"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
750
Search vendor "Sap" for product "Business Warehouse" and version "750"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
751
Search vendor "Sap" for product "Business Warehouse" and version "751"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
752
Search vendor "Sap" for product "Business Warehouse" and version "752"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
753
Search vendor "Sap" for product "Business Warehouse" and version "753"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
754
Search vendor "Sap" for product "Business Warehouse" and version "754"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
755
Search vendor "Sap" for product "Business Warehouse" and version "755"
-
Affected
Sap
Search vendor "Sap"
Business Warehouse
Search vendor "Sap" for product "Business Warehouse"
782
Search vendor "Sap" for product "Business Warehouse" and version "782"
-
Affected