Sap business warehouse
This hub aggregates every CVE we track for Sap business warehouse, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
3
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM9HIGH3CRITICAL3LOW1
Monthly trend
2
0
0
0
0
0
1
0
0
1
4
0
0
0
0
0
0
0
0
1
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Sap business warehouse.
- CVE-2026-27681SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse9.9
- CVE-2025-42962Cross-Site Scripting (XSS) vulnerability in SAP Business Warehouse (Business Explorer Web 3.5 loading animation)6.1
- CVE-2025-42960Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA BEx Tools4.3
- CVE-2025-42954Denial of service (DOS) in SAP NetWeaver Business Warehouse (CCAW application)2.7
- CVE-2025-42952Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis7.7
- CVE-2025-42983Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis8.5
- CVE-2025-25244Missing Authorization Check in SAP Business Warehouse (Process Chains)5.7
- CVE-2024-44113Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)4.3
- CVE-2024-41729Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)4.3
- CVE-2024-39595[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation5.4
- CVE-2024-39594[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation6.1
- CVE-2023-33992Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA4.5
- CVE-2021-21466SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function modu...8.8
- CVE-2021-21465The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the dat...9.9
- CVE-2021-21468The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database ...6.5
Product normalization is registry-driven with AI assist and human review. How it works