CVE-2021-33664: XSS
SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAPUI - 750,752,753,754,755, SAPBASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33664?
CVE-2021-33664 is a Cross-Site Scripting (XSS) vulnerability found in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP) versions SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731.
How severe is CVE-2021-33664?
CVE-2021-33664 has a severity rating of 5.4 out of 10, which is considered medium.
How does CVE-2021-33664 affect SAP NetWeaver Application Server ABAP?
CVE-2021-33664 allows an attacker to perform Cross-Site Scripting (XSS) attacks on SAP NetWeaver Application Server ABAP.
Which versions of SAP NetWeaver Application Server ABAP are affected by CVE-2021-33664?
CVE-2021-33664 affects SAP NetWeaver Application Server ABAP versions SAP_UI - 750,752,753,754,755 and SAP_BASIS - 702, 731.
How can I fix CVE-2021-33664?
To fix CVE-2021-33664, update to the latest version of SAP NetWeaver Application Server ABAP and apply the necessary patches and security updates.