CVE-2021-33694: XSS
SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33694?
CVE-2021-33694 has a medium severity rating due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2021-33694?
To mitigate CVE-2021-33694, it is recommended to update SAP Cloud Connector to the latest version that addresses this vulnerability.
Which versions of SAP Cloud Connector are affected by CVE-2021-33694?
CVE-2021-33694 specifically affects SAP Cloud Connector version 2.0.
What type of vulnerability is CVE-2021-33694?
CVE-2021-33694 is classified as a Cross-Site Scripting (XSS) vulnerability that can lead to the execution of stored malicious code.
Who can exploit CVE-2021-33694?
An attacker with Administrator rights can exploit CVE-2021-33694 to inject malicious code into the application's database.