Sploitus

CVE-2021-21465

1 known exploit for CVE-2021-21465

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

Affected products
Bw Database Interface
Sap Business Warehouse
= 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 782
CVSS 3.1
9.9 CRITICAL
EPSS
3.7% (89th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2021-01-12
CVE-2021-21465 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-21465

Proof-of-concept code and exploit modules indexed by Sploitus