CVE-2021-21444: Medium severity sap businessobjects business intelligence platform vulnerability
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21444?
CVE-2021-21444 is a vulnerability in SAP Business Objects BI Platform versions 410, 420, and 430 that allows multiple X-Frame-Options headers entries in the response headers, potentially leading to a Clickjacking attack.
What is the severity of CVE-2021-21444?
CVE-2021-21444 has a severity level of medium rated 6.1 according to the Common Vulnerability Scoring System (CVSS).
How does CVE-2021-21444 affect SAP Business Objects BI Platform?
CVE-2021-21444 affects SAP Business Objects BI Platform versions 410, 420, and 430 by allowing multiple X-Frame-Options headers entries in the response headers, which may nullify the added X-Frame-Options header and enable Clickjacking attacks.
How can I fix CVE-2021-21444 in SAP Business Objects BI Platform?
To fix CVE-2021-21444 in SAP Business Objects BI Platform, update to the latest version provided by SAP and follow the recommendations provided in their security advisory.
Where can I find more information about CVE-2021-21444?
You can find more information about CVE-2021-21444 in the SAP support portal: [SAP Note 2935791](https://launchpad.support.sap.com/#/notes/2935791) and the [SAP Community Network (SCN) wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543).