CVE-2021-42061Cross-site Scripting in SE SAP Businessobjects Business Intelligence Platform

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 46.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateDec 15

Description

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data from the victim but will never be able to modify the document and publish these modifications to the server. It impacts the "Quick Prompt" workflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

🔴Vulnerability Details

2
GHSA
GHSA-3h3c-qxj3-9h67: SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in2021-12-15
CVEList
CVE-2021-42061: SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in2021-12-14
CVE-2021-42061 — Cross-site Scripting | cvebase