X-Frame-Options Vulnerability in SAP Business Objects BI Platform
CVE-2021-21444
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 February 2021
What is CVE-2021-21444?
The SAP Business Objects BI Platform is susceptible to an issue where multiple entries of the X-Frame-Options header in the HTTP response can be treated unpredictably by different user agents. This mismanagement can lead to potential Clickjacking attacks, where an attacker tricks users into clicking on something different from what the user perceives, thereby compromising their actions on the website.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) < 410 < 410
SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) < 420 < 420
SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) < 430 < 430
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved