First published: Tue Feb 09 2021(Updated: )
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP UI5 | <1.38.49 | |
SAP UI5 | >=1.50.5<1.52.49 | |
SAP UI5 | >=1.60.1<1.60.34 | |
SAP UI5 | >=1.71.0<1.71.31 | |
SAP UI5 | >=1.78.0<1.78.18 | |
SAP UI5 | >=1.84.0<1.84.5 | |
SAP UI5 | >=1.85.0<1.85.4 | |
SAP UI5 | >=1.86.0<1.86.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21476 is a vulnerability in SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 that allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
CVE-2021-21476 has a severity rating of 6.1 (medium).
To fix CVE-2021-21476, update SAP UI5 to version 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, or 1.86.1 or later.
You can find more information about CVE-2021-21476 in the SAP Launchpad support notes (https://launchpad.support.sap.com/#/notes/3014303) and SAP SCN wiki (https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543).
The CWE of CVE-2021-21476 is 601.