Cross-Site Scripting Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2021-33665
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 June 2021
What is CVE-2021-33665?
The SAP NetWeaver Application Server ABAP has a vulnerability that arises from inadequate encoding of user-controlled inputs. This oversight permits attackers to exploit Cross-Site Scripting (XSS) weakness, potentially allowing them to inject malicious scripts into web pages viewed by other users. Such attacks can lead to unauthorized actions being performed on behalf of users, compromising user data and application integrity.
Affected Version(s)
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML) < KRNL64NUC - 7.49 < KRNL64NUC - 7.49
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML) < KRNL64UC - 7.49 < KRNL64UC - 7.49
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML) < 7.53 < 7.53