First published: Wed Sep 15 2021(Updated: )
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP BusinessObjects Business Intelligence Platform vulnerability is CVE-2021-33697.
The severity of CVE-2021-33697 is medium.
The affected software for CVE-2021-33697 is SAP BusinessObjects Business Intelligence Platform versions 420 and 430.
An unauthenticated attacker can exploit CVE-2021-33697 by redirecting users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Yes, there are references for CVE-2021-33697. You can find them at the following links: [link1](https://launchpad.support.sap.com/#/notes/3063048) and [link2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806).