← Back to browse · API

CVE-2021-21466

Severity
CRITICAL
CVSS
9.9
EPSS
0.03078
Risk score
40.68
CISA KEV
No
PoC
No
Published
2021-01-12
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-8740, GHSA-XCP4-49MJ-2J86
Products
SAP SE:SAP BW/4HANA < 100, SAP SE:SAP BW/4HANA < 200, SAP SE:SAP Business Warehouse < 700, SAP SE:SAP Business Warehouse < 701, SAP SE:SAP Business Warehouse < 702, SAP SE:SAP Business Warehouse < 711, SAP SE:SAP Business Warehouse < 730, SAP SE:SAP Business Warehouse < 731, SAP SE:SAP Business Warehouse < 740, SAP SE:SAP Business Warehouse < 750, SAP SE:SAP Business Warehouse < 782
Sources
euvd EUVD-2021-8740

Description

SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.

References