Vulnerabilities > SAP > Businessobjects Business Intelligence > 410

DATE CVE VULNERABILITY TITLE RISK
2021-02-09 CVE-2021-21444 Improper Restriction of Rendered UI Layers or Frames vulnerability in SAP Businessobjects Business Intelligence 410/420/430
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents.
network
sap CWE-1021
5.8
2021-01-12 CVE-2021-21447 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 410/420
SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.
network
sap CWE-79
3.5