CVE-2021-21466: fallo crítico en SAP Business Warehouse
Publicada el · Actualizada el
48Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 9.9epss 3.1%
probabilidad de explotación
3.1%top 13% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
PoCs públicas encontradas — 1
cve_referencepacketstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — SAP Business Warehouse
En el mismo producto, de las más peligrosas a las menos.
Referencias
http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.htmlhttp://seclists.org/fulldisclosure/2022/May/42https://launchpad.support.sap.com/#/notes/2999854https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476