The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-01-12 15:15
Updated : 2022-05-19 18:15
NVD link : CVE-2021-21468
Mitre link : CVE-2021-21468
JSON object : View
Products Affected
sap
- business_warehouse
CWE
CWE-862
Missing Authorization
