CVE-2021-21490

Description

SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.248

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 731Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAPWindows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 752Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 700Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 710Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 730Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 711Windows
Vulnerabilities CVE-2020-6270,CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75aWindows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 702Windows
Vulnerabilities CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver Application Server ABAP 75fWindows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 710Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 711Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 730Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 750Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 752Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 700Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 731Windows
Vulnerabilities CVE-2020-6270,CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75aWindows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 702Windows
Vulnerabilities CVE-2021-21490,CVE-2021-33678 are affected in SAP NetWeaver and ABAP platform (ST-PI) 75fWindows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234