First published: Wed Sep 15 2021(Updated: )
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-33696 is medium with a CVSS score of 5.4.
An authorized attacker can exploit CVE-2021-33696 by exploiting a XSS vulnerability in SAP BusinessObjects Business Intelligence Platform (Crystal Report) versions 420 and 430.
CVE-2021-33696 can lead to non-permanently defacing or modifying displayed content on a website.
SAP BusinessObjects Business Intelligence Platform versions 420 and 430 are affected by CVE-2021-33696.
To fix CVE-2021-33696, update to a patched version or apply the necessary security patches provided by SAP.