CVE-2021-33679 Information
Jun 07, 2022
cve
Description
The SAP BusinessObjects BI Platform version - 420 allows an attacker who has basic access to the application to inject a malicious script while creating a new module document file or folder. When another user visits that page the stored malicious script will execute in their session hence allowing the attacker to compromise their confidentiality and integrity.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://launchpad.support.sap.com/#/notes/3055180 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: