Stored Cross-Site Scripting Vulnerability in SAP NetWeaver Enterprise Portal
CVE-2021-33702
What is CVE-2021-33702?
SAP NetWeaver Enterprise Portal versions 7.10 through 7.50 exhibit a vulnerability which allows an attacker to exploit insufficient encoding of report data. By injecting malicious scripts into reports, an attacker can compromise users when they open these reports, triggering the execution of harmful scripts in their browsers. This results in a Stored XSS vulnerability, posing significant risks to user data and system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver Enterprise Portal < 7.10 < 7.10
SAP NetWeaver Enterprise Portal < 7.11 < 7.11
SAP NetWeaver Enterprise Portal < 7.20 < 7.20
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved