Reverse Tabnabbing Vulnerability in SAP Web Dynpro ABAP
CVE-2021-21478
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 February 2021
What is CVE-2021-21478?
A Reverse Tabnabbing vulnerability in SAP Web Dynpro ABAP enables attackers to exploit the user interface, leading to potential redirection of users to malicious websites. This can occur when a user interacts with a link, and an attacker can manipulate the behavior of the target page, prompting the browser to navigate away from the original website without the user's consent. This creates a risk of credential theft and serves as a pathway for phishing attacks, compromising sensitive information and user security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver AS ABAP (Web Dynpro ABAP) < SAP_UI 750 < SAP_UI 750
SAP NetWeaver AS ABAP (Web Dynpro ABAP) < 752 < 752
SAP NetWeaver AS ABAP (Web Dynpro ABAP) < 753 < 753
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved