HotNews
SAP security note 2986980, "[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)", is a program error note released on 09.02.2021. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Security Note addresses critical vulnerabilities identified in the SAP Business Warehouse Database Interface. Two main vulnerabilities are highlighted:
1. SQL Injection (CVE-2021-21465, CVSS 9.9): An attacker with low privileges can execute crafted database queries, leading to complete compromise of the affected SAP system.
2. Missing Authorization Check (CVE-2021-21468, CVSS 6.5): Allows escalation of privileges, enabling users to read unauthorized database tables.
Solution
The vulnerabilities have been addressed by disabling the affected function module. After applying this note, any call to the function will result in a system dump. To resolve the issue, implement the attached correction instructions or apply the equivalent support package available here.
CVSS
Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected components
- SAP_BW 700 to 755, 782
- SAP_BW_VIRTUAL_COMP 701
Full note on SAP: SAP Support Launchpad note 2986980
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



