First published: Wed Jun 09 2021(Updated: )
SAP Manufacturing Execution versions - 15.1, 1.5.2, 15.3, 15.4, does not contain some HTTP security headers in their HTTP response. The lack of these headers in response can be exploited by the attacker to execute Cross-Site Scripting (XSS) attacks.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Manufacturing Execution | =15.1 | |
SAP Manufacturing Execution | =15.2 | |
SAP Manufacturing Execution | =15.3 | |
SAP Manufacturing Execution | =15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-27615.
The severity of CVE-2021-27615 is medium with a score of 5.4.
SAP Manufacturing Execution versions 15.1, 1.5.2, 15.3, and 15.4 are affected by CVE-2021-27615.
CVE-2021-27615 can be exploited by attackers to execute Cross-Site Scripting (XSS) attacks.
To fix CVE-2021-27615, it is recommended to apply the necessary patches provided by SAP and ensure proper configuration of HTTP security headers in the SAP Manufacturing Execution versions mentioned.