Aller au contenu

Fiche vulnérabilité

CVE-2021-21466 : faille élevée sap business warehouse (CVSS 8.8)

Description

SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 janv. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • sap business warehouse
  • sap bw\/4hana

Références

Rechercher une autre vulnérabilité dans la base CVE