First published: Tue Jan 12 2021(Updated: )
SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =410 | |
SAP BusinessObjects Business Intelligence | =420 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-21447.
The severity of CVE-2021-21447 is medium.
An attacker can exploit this vulnerability by injecting a malicious JavaScript payload into the custom value input field of an Input Control in SAP BusinessObjects Business Intelligence platform versions 410 and 420.
Users of SAP BusinessObjects Business Intelligence platform versions 410 and 420 are affected by CVE-2021-21447.
Yes, SAP has provided fixes and patches for CVE-2021-21447. Please refer to the following references for more information: [link1](https://launchpad.support.sap.com/#/notes/2965154) and [link2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476).