Stored Cross-Site Scripting in SAP Manufacturing Execution by SAP
CVE-2021-27600

6.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 April 2021

Summary

SAP Manufacturing Execution (System Rules) versions 15.1, 15.2, 15.3, and 15.4 are susceptible to a Stored Cross-Site Scripting vulnerability. This arises from a failure to adequately encode certain HTTP parameters, allowing authorized attackers to inject malicious scripts into the application. Once embedded, these scripts can be executed in the context of the user’s browser, enabling unauthorized access to sensitive information, modification of data, and potential exploitation of user sessions. Although the integrity of the server remains intact, the exposure of sensitive information poses significant security risks to users.

Affected Version(s)

SAP Manufacturing Execution (System Rules) < 15.1 < 15.1

SAP Manufacturing Execution (System Rules) < 15.2 < 15.2

SAP Manufacturing Execution (System Rules) < 15.3 < 15.3

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.