CVE-2021-33679: XSS
The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored malicious script will execute in their session, hence allowing the attacker to compromise their confidentiality and integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33679?
The severity of CVE-2021-33679 is medium with a severity value of 5.4.
How does CVE-2021-33679 impact SAP BusinessObjects BI Platform version 420?
CVE-2021-33679 allows an attacker with basic access to the application to inject a malicious script and execute it in another user's session.
How can I fix CVE-2021-33679 vulnerability?
To fix the CVE-2021-33679 vulnerability, apply the necessary updates or patches provided by SAP BusinessObjects BI Platform.
How can I protect my SAP BusinessObjects BI Platform version 420 from CVE-2021-33679?
To protect your SAP BusinessObjects BI Platform version 420 from CVE-2021-33679, restrict access to the application and ensure that only authenticated and authorized users have access.
What is CWE-79?
CWE-79 refers to an improper neutralization of input during web page generation vulnerability, also known as cross-site scripting (XSS).