Vulnerabilities > SAP > Business Warehouse > 755

DATE CVE VULNERABILITY TITLE RISK
2021-01-12 CVE-2021-21468 Missing Authorization vulnerability in SAP Business Warehouse
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
network
low complexity
sap CWE-862
6.5
2021-01-12 CVE-2021-21465 SQL Injection vulnerability in SAP Business Warehouse
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database.
network
low complexity
sap CWE-89
6.5
2020-12-09 CVE-2020-26838 OS Command Injection vulnerability in SAP Business Warehouse and Bw/4Hana
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction.
network
low complexity
sap CWE-78
critical
9.0