First published: Tue Aug 10 2021(Updated: )
SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Knowledge Management | =7.30 | |
SAP NetWeaver Knowledge Management | =7.31 | |
SAP NetWeaver Knowledge Management | =7.40 | |
SAP NetWeaver Knowledge Management | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33707 is a vulnerability in SAP NetWeaver Knowledge Management that allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component.
CVE-2021-33707 affects SAP NetWeaver Knowledge Management by enabling remote attackers to redirect users to arbitrary websites and conduct phishing attacks.
CVE-2021-33707 has a severity of medium with a CVSS score of 6.1.
CVE-2021-33707 can be exploited by remote attackers by using a URL stored in a component to redirect users to arbitrary websites.
Yes, SAP has released a security note with a fix for CVE-2021-33707. It is recommended to apply the necessary updates to address this vulnerability.