Cross-Site Scripting Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2021-33665
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 9 June 2021
Summary
The SAP NetWeaver Application Server ABAP has a vulnerability that arises from inadequate encoding of user-controlled inputs. This oversight permits attackers to exploit Cross-Site Scripting (XSS) weakness, potentially allowing them to inject malicious scripts into web pages viewed by other users. Such attacks can lead to unauthorized actions being performed on behalf of users, compromising user data and application integrity.
Affected Version(s)
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML) < KRNL64NUC - 7.49 < KRNL64NUC - 7.49
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML) < KRNL64UC - 7.49 < KRNL64UC - 7.49
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML) < 7.53 < 7.53
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved