Vulnerabilities > CVE-2021-33702 - Unspecified vulnerability in SAP Netweaver Enterprise Portal
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the malicious script gets executed in the victim's browser, resulting in a Stored Cross-Site Scripting (XSS) vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
References
- http://packetstormsecurity.com/files/165737/SAP-Enterprise-Portal-NavigationReporter-Cross-Site-Scripting.html
- http://packetstormsecurity.com/files/165737/SAP-Enterprise-Portal-NavigationReporter-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2022/Jan/70
- http://seclists.org/fulldisclosure/2022/Jan/70
- https://launchpad.support.sap.com/#/notes/3073681
- https://launchpad.support.sap.com/#/notes/3073681
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806