Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2021-21466 Code Injection in SAP Business Warehouse and SAP BW/4HANA, SAP security note 2999854

SAP Note 2999854
HotNews

SAP security note 2999854, "[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA", released on April 27, 2021. Below are the symptom, SAP recommended solution and the affected software components.

ComponentInterface to Database (BW-BEX-OT-DBIF)
PriorityHotNews
StatusReleased for Customer
Released onApril 27, 2021

Description

Symptom

SAP Business Warehouse and SAP BW/4HANA are vulnerable to a code injection flaw that allows a low-privileged attacker to inject malicious ABAP code using a remote-enabled function module over the network. Due to insufficient input validation, an attacker with S_RFC access can execute this function module to insert malicious code, which is then saved persistently in a report within the ABAP repository. Executing this report can lead to:

  • Sensitive data loss
  • Modification of critical data
  • Denial of service

Solution

To mitigate this vulnerability, implement the correction instructions provided in the SAP Note. The solution involves adding additional validation for all input data in the affected function to prevent malicious inputs from reaching the database.

CVSS

Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

Affected components

  • DW4CORE: 100, 200
  • SAP_BW: 700 to 702, 711, 730 to 731, 740, 750 to 755, 782

Full note on SAP: SAP Support Launchpad note 2999854

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More