CVE-2021-21476: Medium severity sap openui5 vulnerability
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21476?
CVE-2021-21476 is a vulnerability in SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 that allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
How severe is CVE-2021-21476?
CVE-2021-21476 has a severity rating of 6.1 (medium).
How can I fix CVE-2021-21476?
To fix CVE-2021-21476, update SAP UI5 to version 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, or 1.86.1 or later.
Where can I find more information about CVE-2021-21476?
You can find more information about CVE-2021-21476 in the SAP Launchpad support notes (https://launchpad.support.sap.com/#/notes/3014303) and SAP SCN wiki (https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543).
What is the CWE of CVE-2021-21476?
The CWE of CVE-2021-21476 is 601.