CVE-2021-33679
Last modified
CVE-2021-33679 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored malicious script will execute in their session, hence allowing the attacker to compromise their confidentiality and integrity.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored malicious script will execute in their session, hence allowing the attacker to compromise their confidentiality and integrity.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence Platform | 420 |
References
- https://launchpad.support.sap.com/#/notes/3055180Permissions Required
- https://launchpad.support.sap.com/#/notes/3055180Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33679?
How severe is CVE-2021-33679?
How do I fix CVE-2021-33679?
Are you affected by CVE-2021-33679?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
