CVE-2021-21447
5.4MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 12 January 2021
Summary
SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.
Affected Version(s)
SAP BusinessObjects Business Intelligence platform (Web Intelligence HTML interface) < 410 < 410
SAP BusinessObjects Business Intelligence platform (Web Intelligence HTML interface) < 420 < 420
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved