CVE-2023-0016

SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:business_planning_and_consolidation:800:*:*:*:*:microsoft:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:810:*:*:*:*:microsoft:*:*

History

No history.

Information

Published : 2023-01-10 04:15

Updated : 2024-02-28 19:51


NVD link : CVE-2023-0016

Mitre link : CVE-2023-0016

CVE.ORG link : CVE-2023-0016


JSON object : View

Products Affected

sap

  • business_planning_and_consolidation
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')