SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3004043 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-06-09 07:15
Updated : 2022-10-05 07:16
NVD link : CVE-2021-21490
Mitre link : CVE-2021-21490
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
sap
- netweaver_application_server_abap