CVE-2021-33687: Infoleak
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33687?
The severity of CVE-2021-33687 is medium with a CVSS score of 4.9.
How does CVE-2021-33687 affect SAP NetWeaver AS JAVA (Enterprise Portal)?
CVE-2021-33687 affects SAP NetWeaver AS JAVA (Enterprise Portal) versions 7.10, 7.20, 7.30, 7.31, 7.40, and 7.50.
What does CVE-2021-33687 reveal in SAP NetWeaver AS JAVA (Enterprise Portal)?
CVE-2021-33687 reveals sensitive information in one of the HTTP requests made by SAP NetWeaver AS JAVA (Enterprise Portal).
How can an attacker exploit CVE-2021-33687?
An attacker can use CVE-2021-33687 in conjunction with other attacks, such as XSS, to steal sensitive information.
Are there any fixes or patches available for CVE-2021-33687?
Yes, SAP has released a security note (3059764) with information on how to mitigate the vulnerability.