CVE-2021-21465
SAP Application Server ABAP / ABAP Platform Code Injection / SQL Injection / Missing Authorization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.
La Interfaz de Base de Datos de BW permite a un atacante con pocos privilegios ejecutar cualquier consulta de la base de datos diseñada, exponiendo la base de datos del backend. Un atacante puede incluir sus propios comandos SQL que la base de datos ejecutará sin sanear apropiadamente los datos no confiables, conllevando a una vulnerabilidad de inyección SQL que puede comprometer por completo el sistema SAP afectado
The SAP application server ABAP and ABAP Platform are susceptible to code injection, SQL injection, and missing authorization vulnerabilities. Multiple SAP products are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-30 CVE Reserved
- 2021-01-12 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-09-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476 | 2022-06-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 710 Search vendor "Sap" for product "Business Warehouse" and version "710" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 711 Search vendor "Sap" for product "Business Warehouse" and version "711" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 730 Search vendor "Sap" for product "Business Warehouse" and version "730" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 731 Search vendor "Sap" for product "Business Warehouse" and version "731" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 740 Search vendor "Sap" for product "Business Warehouse" and version "740" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 750 Search vendor "Sap" for product "Business Warehouse" and version "750" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 751 Search vendor "Sap" for product "Business Warehouse" and version "751" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 752 Search vendor "Sap" for product "Business Warehouse" and version "752" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 753 Search vendor "Sap" for product "Business Warehouse" and version "753" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 754 Search vendor "Sap" for product "Business Warehouse" and version "754" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 755 Search vendor "Sap" for product "Business Warehouse" and version "755" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Business Warehouse Search vendor "Sap" for product "Business Warehouse" | 782 Search vendor "Sap" for product "Business Warehouse" and version "782" | - |
Affected
|