Search Icon

SAP Security Notes Review: January 2021

12 January 2021

banner image

SAP’s security patch day for January 2021 has seen the release of 10 OSS SAP security notes and 7 updates to existing notes. 1 OSS notes has been classified as low, 10 OSS notes have been classified as medium, 1 OSS notes has been classified as high and 5 as critical, based on CVSS v3.0 Rating.

January 2021 CVSS v3 Base Score Graph

3 OSS notes have been released this month for SAP NetWeaver AS JAVA and SAP Business Warehouse.  2 notes have been released for SAP NetWeaver AS ABAP.  Single notes have been released for SAP Business Client, SAP Commerce Cloud, SAP BusinessObjects, SAP Master Data Governance, SAP GUI, SAP NetWeaver Master Data Management, SAP 3D Visual Enterprise Viewer, SAP Banking Services and SAP EPM ADD-IN.

January 2021 Product Category Graph

 

Vulnerabilities: January 2021 Highlights

[CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface) (SAP Note 2986980)

Two vulnerabilities have been discovered in SAP BW:

SQL Injection – An attacker with low level privileges can execute SQL commands which the database will run without properly sanitizing the untrusted data leading to SQL injection vulnerability.  This can fully compromise an affected system.

Missing Authorisation Checks – The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA (SAP Note 2999854)

SAP Business Warehouse and SAP BW/4HANA allow a low privileged attacker to inject code using a remote enabled function module over the network. This is due to a lack of input validation, an attacker with appropriate access can execute the function module and inject malicious ABAP code.

[CVE-2021-21446] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform (SAP Note 3000306)

SAP NetWeaver AS ABAP and ABAP Platform allow an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.  ABAP Server’s and ABAP Platform’s ABAP Keyword Documentation come with a set of demo examples, embedded in the documentation. When executing such examples from the web version of the ABAP Keyword Documentation, users can lock themselves, which is experienced for these users as “service not available”.

Related Blogs

AI-First SAP SuccessFactors AMS Blog Banner Image

01 September 2026

Reimagining SuccessFactors Support: From Tickets to Intelligence: An AI-First AMS Model

SAP SuccessFactors Agentic AI: Joule and AI Agents

24 August 2026

SAP SuccessFactors - From Systems of Record to Systems of Intelligence

Pricefx blog banner

21 August 2026

"We Already Have a CRM." Why That Isn't a Pricing Strategy.

Leveraging claude in sap successfactors

17 August 2026

Leveraging claude in sap successfactors

AI-embedded SAP Blog banner

29 July 2026

AI Built In, Not Bolted On: What AI-Embedded AMS Actually Looks Like

Rethinking blog banner

28 July 2026

Rethinking Application Managed Services for HR Shared Services

successfactor blog banner

22 July 2026

Is Your SAP SuccessFactors Environment Ready for SAP Business AI and Joule?

Pricefx Certified

13 July 2026

Beyond the Platform: Why Certified Pricefx Experts Make the Difference