Code Injection in SAP Business Warehouse - CVE-2021-21466

 

Code Injection in SAP Business Warehouse - CVE-2021-21466

Published: January 12, 2021 / Updated: May 11, 2021


Vulnerability identifier: #VU49493
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-21466
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
SAP Business Warehouse
Software vendor:
SAP

Description

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote user can send a specially crafted request and execute arbitrary code using a remote enabled function module, create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a DoS.



Remediation

Install updates from vendor's website.

External links