CVE-2021-33666: XSS
Published Jun 9, 2021
·Updated
When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation.
Affected Software
1 affected component
SAP Commerce Cloud=100
Event History
Jun 9, 2021
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-33666.
2
What is the severity of CVE-2021-33666?
The severity of CVE-2021-33666 is medium with a CVSS score of 6.1.
3
How does CVE-2021-33666 affect SAP Commerce Cloud?
CVE-2021-33666 affects SAP Commerce Cloud version 100 when hosting a JavaScript storefront.
4
What is the potential impact of CVE-2021-33666?
CVE-2021-33666 could be used to facilitate an XSS attack or malware proliferation.
5
Are there any references for further information about CVE-2021-33666?
Yes, you can find more information about CVE-2021-33666 at the following references: [Reference 1](https://launchpad.support.sap.com/#/notes/2985562), [Reference 2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999).