CVE-2021-33702: XSS
Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the malicious script gets executed in the victim's browser, resulting in a Stored Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33702?
CVE-2021-33702 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2021-33702?
To fix CVE-2021-33702, you should update your SAP NetWeaver Enterprise Portal to the latest patched version.
What versions of SAP NetWeaver are affected by CVE-2021-33702?
CVE-2021-33702 affects SAP NetWeaver Enterprise Portal versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
What type of attack can be executed using CVE-2021-33702?
CVE-2021-33702 allows attackers to execute cross-site scripting (XSS) by injecting malicious scripts into report data.
Is user interaction required for a successful attack with CVE-2021-33702?
Yes, a victim must open the infected report for a successful attack of CVE-2021-33702.