Cross-Site Scripting Issue in SAP NetWeaver Development Infrastructure
CVE-2021-33691
6.9MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 15 September 2021
What is CVE-2021-33691?
The NWDI Notification Service in certain versions of SAP NetWeaver Development Infrastructure has a vulnerability due to insufficient encoding of user-controlled inputs. This flaw allows malicious actors to inject crafted scripts that can execute within the context of the victim's session. If a user is active and engaged with the system when the script runs, it can lead to unauthorized access to sensitive session information, potentially compromising the user's data and security.
Affected Version(s)
SAP NetWeaver Development Infrastructure (Notification Service) < 7.31 < 7.31
SAP NetWeaver Development Infrastructure (Notification Service) < 7.40 < 7.40
SAP NetWeaver Development Infrastructure (Notification Service) < 7.50 < 7.50