CVE-2021-33696: XSS
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33696?
The severity of CVE-2021-33696 is medium with a CVSS score of 5.4.
How can an attacker exploit CVE-2021-33696?
An authorized attacker can exploit CVE-2021-33696 by exploiting a XSS vulnerability in SAP BusinessObjects Business Intelligence Platform (Crystal Report) versions 420 and 430.
What is the impact of CVE-2021-33696?
CVE-2021-33696 can lead to non-permanently defacing or modifying displayed content on a website.
Which versions of SAP BusinessObjects Business Intelligence Platform are affected by CVE-2021-33696?
SAP BusinessObjects Business Intelligence Platform versions 420 and 430 are affected by CVE-2021-33696.
How do I fix CVE-2021-33696?
To fix CVE-2021-33696, update to a patched version or apply the necessary security patches provided by SAP.