Description
SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8763 | SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user. |
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-03T18:16:22.657Z
Reserved: 2020-12-30T00:00:00.000Z
Link: CVE-2021-21490
No data.
Status : Modified
Published: 2021-06-09T14:15:08.010
Modified: 2024-11-21T05:48:28.693
Link: CVE-2021-21490
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD