Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-04302
HistoryJan 12, 2023 - 12:00 a.m.

SAP BPC MS SQL Injection Vulnerability

2023-01-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
sap bpc ms
sql injection
vulnerability
sap germany
attackers
sensitive data

EPSS

0.001

Percentile

36.9%

SAP BPC MS is a business planning and consolidation application from SAP Germany that provides planning, budgeting, forecasting, and financial consolidation functions. SAP BPC MS version 10.0 810 contains a SQL injection vulnerability that stems from the application’s lack of validation of externally entered SQL statements, which can be exploited by attackers to execute illegal SQL commands to steal sensitive database data.

EPSS

0.001

Percentile

36.9%

Related for CNVD-2023-04302