CVE-2021-33694

Severity
4.8MEDIUM
EPSS
0.2%
top 63.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateMay 24

Description

SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f42x-6gqm-cmqq: SAP Cloud Connector, version - 22022-05-24
CVEList
CVE-2021-33694: SAP Cloud Connector, version - 22021-09-15
CVE-2021-33694 (MEDIUM CVSS 4.8) | SAP Cloud Connector | cvebase.io