Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8424-8x2w-j5fr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

EPSS

Процентиль: 80%
0.01427
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.9
nvd
около 5 лет назад

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

EPSS

Процентиль: 80%
0.01427
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-89