Description
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8718 | SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack. |
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-03T18:16:22.235Z
Reserved: 2020-12-30T00:00:00.000Z
Link: CVE-2021-21444
No data.
Status : Modified
Published: 2021-02-09T21:15:13.083
Modified: 2024-11-21T05:48:23.200
Link: CVE-2021-21444
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD