Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
HANABPC 810
affected
BPC4HANA 300
affected
SAP_BW 750
affected
752
affected
753
affected
754
affected
755
affected
756
affected
757
affected
758
affected
816
affected
Description
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command
Product status
HANABPC 810
BPC4HANA 300
SAP_BW 750
752
753
754
755
756
757
758
816