Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2021-21465 Multiple vulnerabilities in SAP Business Warehouse (Database Interface), SAP security note 2986980

SAP Note 2986980
HotNews

SAP security note 2986980, "[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)", is a program error note released on 09.02.2021. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityHotNews
StatusReleased for Customer
Released on09.02.2021

Description

Symptom

This SAP Security Note addresses critical vulnerabilities identified in the SAP Business Warehouse Database Interface. Two main vulnerabilities are highlighted:

1. SQL Injection (CVE-2021-21465, CVSS 9.9): An attacker with low privileges can execute crafted database queries, leading to complete compromise of the affected SAP system.

2. Missing Authorization Check (CVE-2021-21468, CVSS 6.5): Allows escalation of privileges, enabling users to read unauthorized database tables.

Solution

The vulnerabilities have been addressed by disabling the affected function module. After applying this note, any call to the function will result in a system dump. To resolve the issue, implement the attached correction instructions or apply the equivalent support package available here.

CVSS

Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected components

  • SAP_BW 700 to 755, 782
  • SAP_BW_VIRTUAL_COMP 701

Full note on SAP: SAP Support Launchpad note 2986980

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More