cbcvebase.
CVE-2021-21490
published 2021-06-09

CVE-2021-21490: SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user.

Affected

23 ranges
VendorProductVersion rangeFixed in
gnubinutils>= 0 < 2.24-5ubuntu14.2+esm32.24-5ubuntu14.2+esm3
gnubinutils>= 0 < 2.26.1-1ubuntu1~16.04.8+esm72.26.1-1ubuntu1~16.04.8+esm7
gnubinutils>= 0 < 2.30-21ubuntu1~18.04.9+esm12.30-21ubuntu1~18.04.9+esm1
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sap_sesap_netweaver_as_for_abap< 700700
sap_sesap_netweaver_as_for_abap< 702702
sap_sesap_netweaver_as_for_abap< 710710
sap_sesap_netweaver_as_for_abap< 711711
sap_sesap_netweaver_as_for_abap< 730730
sap_sesap_netweaver_as_for_abap< 731731
sap_sesap_netweaver_as_for_abap< 750750
sap_sesap_netweaver_as_for_abap< 752752
sap_sesap_netweaver_as_for_abap< 75A75A
sap_sesap_netweaver_as_for_abap< 75F75F

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv5.5MEDIUM