← back
CVE-2023-0016

SQL Injection vulnerability in SAP Business Planning and Consolidation MS

CVSS 9.9 CRITICALEPSS 0.6%CWE-89
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.9EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Jan 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
SAP · SAP BPC MS 10.0

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →