Cross-Site Scripting Issue in SAP NetWeaver Development Infrastructure
CVE-2021-33691

6.9MEDIUM

What is CVE-2021-33691?

The NWDI Notification Service in certain versions of SAP NetWeaver Development Infrastructure has a vulnerability due to insufficient encoding of user-controlled inputs. This flaw allows malicious actors to inject crafted scripts that can execute within the context of the victim's session. If a user is active and engaged with the system when the script runs, it can lead to unauthorized access to sensitive session information, potentially compromising the user's data and security.

Affected Version(s)

SAP NetWeaver Development Infrastructure (Notification Service) < 7.31 < 7.31

SAP NetWeaver Development Infrastructure (Notification Service) < 7.40 < 7.40

SAP NetWeaver Development Infrastructure (Notification Service) < 7.50 < 7.50

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.