Reverse Tabnabbing Vulnerability in SAP UI5
CVE-2021-21476

4.7MEDIUM

Key Information:

Vendor
SAP
Status
Vendor
CVE Published:
9 February 2021

Summary

Several versions of SAP UI5 are susceptible to a reverse tabnabbing vulnerability that enables unauthenticated attackers to redirect users to malicious websites. This occurs when users are led to an external link from the application, potentially compromising sensitive information and undermining user trust in the platform. Addressing this vulnerability is crucial for maintaining user safety and protecting against phishing attempts.

Affected Version(s)

SAP UI5 < 1.38.49 < 1.38.49

SAP UI5 < 1.52.49 < 1.52.49

SAP UI5 < 1.60.34 < 1.60.34

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.