Логотип exploitDog
bind:CVE-2021-21465
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21465

Количество 2

Количество 2

nvd логотип

CVE-2021-21465

около 5 лет назад

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-8424-8x2w-j5fr

больше 3 лет назад

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21465

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

CVSS3: 9.9
1%
Низкий
около 5 лет назад
github логотип
GHSA-8424-8x2w-j5fr

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

CVSS3: 9.9
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу