ZeroHour

CVE-2021-21468

PoC ×2
CVSS 3.1
6.5 medium
EPSS
2%p78
Published
()
Modified
Description

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

Vendors
sap
Products
business warehouse
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news