Code Injection in SAP Business Warehouse - CVE-2021-21466
Published: January 12, 2021 / Updated: May 11, 2021
SAP Business Warehouse
SAP
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote user can send a specially crafted request and execute arbitrary code using a remote enabled function module, create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a DoS.