CVE-2021-21468

MEDIUM

SAP Business Warehouse - Missing Authorization in BW Database Interface

Title source: llm
STIX 2.1

Description

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

References (4)

Core 4
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2986980
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/May/42

Scores

CVSS v3 6.5
EPSS 0.0045
EPSS Percentile 63.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-862
Status published
Products (12)
sap/business_warehouse 710
sap/business_warehouse 711
sap/business_warehouse 730
sap/business_warehouse 731
sap/business_warehouse 740
sap/business_warehouse 750
sap/business_warehouse 751
sap/business_warehouse 752
sap/business_warehouse 753
sap/business_warehouse 754
... and 2 more
Published Jan 12, 2021
Tracked Since Feb 18, 2026