Reverse Tabnabbing Vulnerability in SAP UI5
CVE-2021-21476
4.7MEDIUM
Summary
Several versions of SAP UI5 are susceptible to a reverse tabnabbing vulnerability that enables unauthenticated attackers to redirect users to malicious websites. This occurs when users are led to an external link from the application, potentially compromising sensitive information and undermining user trust in the platform. Addressing this vulnerability is crucial for maintaining user safety and protecting against phishing attempts.
Affected Version(s)
SAP UI5 < 1.38.49 < 1.38.49
SAP UI5 < 1.52.49 < 1.52.49
SAP UI5 < 1.60.34 < 1.60.34
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved