Vulnerabilities > SAP > Business Warehouse > 782

DATE CVE VULNERABILITY TITLE RISK
2021-01-12 CVE-2021-21468 Missing Authorization vulnerability in SAP Business Warehouse
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
network
low complexity
sap CWE-862
6.5
2021-01-12 CVE-2021-21466 Code Injection vulnerability in SAP Business Warehouse and Bw/4Hana
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network.
network
low complexity
sap CWE-94
8.8
2021-01-12 CVE-2021-21465 SQL Injection vulnerability in SAP Business Warehouse
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database.
network
low complexity
sap CWE-89
6.5
2020-12-09 CVE-2020-26838 OS Command Injection vulnerability in SAP Business Warehouse and Bw/4Hana
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction.
network
low complexity
sap CWE-78
critical
9.0