CVE-2021-33694 Information

Description

SAP Cloud Connector version - 2.0 does not sufficiently encode user-controlled inputs allowing an attacker with Administrator rights to include malicious codes that get stored in the database and when accessed could be executed in the application resulting in Stored Cross-Site Scripting.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Reference

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806 https://launchpad.support.sap.com/#/notes/3058553

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

4.8

Share on: