Vulnerability Details CVE-2021-21476
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.6%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 5.8
Products affected by CVE-2021-21476
-
-
-
cpe:2.3:a:sap:ui5:1.22.10
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.26.10
-
cpe:2.3:a:sap:ui5:1.26.11
-
cpe:2.3:a:sap:ui5:1.26.13
-
cpe:2.3:a:sap:ui5:1.26.14
-
cpe:2.3:a:sap:ui5:1.26.16
-
cpe:2.3:a:sap:ui5:1.26.17
-
cpe:2.3:a:sap:ui5:1.26.18
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.28.10
-
cpe:2.3:a:sap:ui5:1.28.11
-
cpe:2.3:a:sap:ui5:1.28.13
-
cpe:2.3:a:sap:ui5:1.28.14
-
cpe:2.3:a:sap:ui5:1.28.15
-
cpe:2.3:a:sap:ui5:1.28.16
-
cpe:2.3:a:sap:ui5:1.28.17
-
cpe:2.3:a:sap:ui5:1.28.18
-
cpe:2.3:a:sap:ui5:1.28.19
-
cpe:2.3:a:sap:ui5:1.28.20
-
cpe:2.3:a:sap:ui5:1.28.21
-
cpe:2.3:a:sap:ui5:1.28.22
-
cpe:2.3:a:sap:ui5:1.28.23
-
cpe:2.3:a:sap:ui5:1.28.24
-
cpe:2.3:a:sap:ui5:1.28.27
-
cpe:2.3:a:sap:ui5:1.28.28
-
cpe:2.3:a:sap:ui5:1.28.29
-
cpe:2.3:a:sap:ui5:1.28.30
-
cpe:2.3:a:sap:ui5:1.28.31
-
cpe:2.3:a:sap:ui5:1.28.32
-
cpe:2.3:a:sap:ui5:1.28.33
-
cpe:2.3:a:sap:ui5:1.28.34
-
cpe:2.3:a:sap:ui5:1.28.35
-
cpe:2.3:a:sap:ui5:1.28.36
-
cpe:2.3:a:sap:ui5:1.28.37
-
cpe:2.3:a:sap:ui5:1.28.38
-
cpe:2.3:a:sap:ui5:1.28.39
-
-
cpe:2.3:a:sap:ui5:1.28.40
-
cpe:2.3:a:sap:ui5:1.28.41
-
cpe:2.3:a:sap:ui5:1.28.42
-
cpe:2.3:a:sap:ui5:1.28.43
-
cpe:2.3:a:sap:ui5:1.28.44
-
cpe:2.3:a:sap:ui5:1.28.45
-
cpe:2.3:a:sap:ui5:1.28.46
-
cpe:2.3:a:sap:ui5:1.28.47
-
cpe:2.3:a:sap:ui5:1.28.48
-
cpe:2.3:a:sap:ui5:1.28.49
-
-
cpe:2.3:a:sap:ui5:1.28.50
-
cpe:2.3:a:sap:ui5:1.28.51
-
cpe:2.3:a:sap:ui5:1.28.52
-
cpe:2.3:a:sap:ui5:1.28.53
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.30.10
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.32.10
-
cpe:2.3:a:sap:ui5:1.32.11
-
cpe:2.3:a:sap:ui5:1.32.12
-
cpe:2.3:a:sap:ui5:1.32.13
-
cpe:2.3:a:sap:ui5:1.32.14
-
cpe:2.3:a:sap:ui5:1.32.15
-
cpe:2.3:a:sap:ui5:1.32.16
-
cpe:2.3:a:sap:ui5:1.32.18
-
-
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.34.10
-
cpe:2.3:a:sap:ui5:1.34.11
-
cpe:2.3:a:sap:ui5:1.34.12
-
cpe:2.3:a:sap:ui5:1.34.13
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.36.10
-
cpe:2.3:a:sap:ui5:1.36.11
-
cpe:2.3:a:sap:ui5:1.36.12
-
cpe:2.3:a:sap:ui5:1.36.13
-
cpe:2.3:a:sap:ui5:1.36.14
-
cpe:2.3:a:sap:ui5:1.36.15
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.38.10
-
cpe:2.3:a:sap:ui5:1.38.11
-
cpe:2.3:a:sap:ui5:1.38.12
-
cpe:2.3:a:sap:ui5:1.38.13
-
cpe:2.3:a:sap:ui5:1.38.14
-
cpe:2.3:a:sap:ui5:1.38.15
-
cpe:2.3:a:sap:ui5:1.38.16
-
cpe:2.3:a:sap:ui5:1.38.17
-
cpe:2.3:a:sap:ui5:1.38.18
-
cpe:2.3:a:sap:ui5:1.38.19
-
cpe:2.3:a:sap:ui5:1.38.20
-
cpe:2.3:a:sap:ui5:1.38.21
-
cpe:2.3:a:sap:ui5:1.38.22
-
cpe:2.3:a:sap:ui5:1.38.23
-
cpe:2.3:a:sap:ui5:1.38.25
-
cpe:2.3:a:sap:ui5:1.38.26
-
cpe:2.3:a:sap:ui5:1.38.28
-
cpe:2.3:a:sap:ui5:1.38.29
-
cpe:2.3:a:sap:ui5:1.38.30
-
cpe:2.3:a:sap:ui5:1.38.31
-
cpe:2.3:a:sap:ui5:1.38.32
-
cpe:2.3:a:sap:ui5:1.38.33
-
cpe:2.3:a:sap:ui5:1.38.34
-
cpe:2.3:a:sap:ui5:1.38.35
-
cpe:2.3:a:sap:ui5:1.38.36
-
cpe:2.3:a:sap:ui5:1.38.37
-
cpe:2.3:a:sap:ui5:1.38.38
-
cpe:2.3:a:sap:ui5:1.38.39
-
cpe:2.3:a:sap:ui5:1.38.40
-
cpe:2.3:a:sap:ui5:1.38.41
-
cpe:2.3:a:sap:ui5:1.38.42
-
cpe:2.3:a:sap:ui5:1.38.43
-
cpe:2.3:a:sap:ui5:1.38.44
-
cpe:2.3:a:sap:ui5:1.38.45
-
cpe:2.3:a:sap:ui5:1.38.46
-
cpe:2.3:a:sap:ui5:1.38.47
-
cpe:2.3:a:sap:ui5:1.38.48
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.50.10
-
cpe:2.3:a:sap:ui5:1.50.11
-
cpe:2.3:a:sap:ui5:1.50.12
-
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.52.10
-
cpe:2.3:a:sap:ui5:1.52.11
-
cpe:2.3:a:sap:ui5:1.52.12
-
cpe:2.3:a:sap:ui5:1.52.13
-
cpe:2.3:a:sap:ui5:1.52.14
-
cpe:2.3:a:sap:ui5:1.52.15
-
cpe:2.3:a:sap:ui5:1.52.16
-
cpe:2.3:a:sap:ui5:1.52.17
-
cpe:2.3:a:sap:ui5:1.52.18
-
cpe:2.3:a:sap:ui5:1.52.19
-
cpe:2.3:a:sap:ui5:1.52.20
-
cpe:2.3:a:sap:ui5:1.52.21
-
cpe:2.3:a:sap:ui5:1.52.22
-
cpe:2.3:a:sap:ui5:1.52.23
-
cpe:2.3:a:sap:ui5:1.52.24
-
cpe:2.3:a:sap:ui5:1.52.25
-
cpe:2.3:a:sap:ui5:1.52.26
-
cpe:2.3:a:sap:ui5:1.52.27
-
cpe:2.3:a:sap:ui5:1.52.28
-
cpe:2.3:a:sap:ui5:1.52.29
-
cpe:2.3:a:sap:ui5:1.52.30
-
cpe:2.3:a:sap:ui5:1.52.31
-
cpe:2.3:a:sap:ui5:1.52.32
-
cpe:2.3:a:sap:ui5:1.52.33
-
cpe:2.3:a:sap:ui5:1.52.34
-
cpe:2.3:a:sap:ui5:1.52.35
-
cpe:2.3:a:sap:ui5:1.52.36
-
cpe:2.3:a:sap:ui5:1.52.37
-
cpe:2.3:a:sap:ui5:1.52.38
-
cpe:2.3:a:sap:ui5:1.52.39
-
-
cpe:2.3:a:sap:ui5:1.52.40
-
cpe:2.3:a:sap:ui5:1.52.41
-
cpe:2.3:a:sap:ui5:1.52.42
-
cpe:2.3:a:sap:ui5:1.52.43
-
cpe:2.3:a:sap:ui5:1.52.44
-
cpe:2.3:a:sap:ui5:1.52.45
-
cpe:2.3:a:sap:ui5:1.52.46
-
cpe:2.3:a:sap:ui5:1.52.47
-
cpe:2.3:a:sap:ui5:1.52.48
-
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.60.10
-
cpe:2.3:a:sap:ui5:1.60.11
-
cpe:2.3:a:sap:ui5:1.60.12
-
cpe:2.3:a:sap:ui5:1.60.13
-
cpe:2.3:a:sap:ui5:1.60.14
-
cpe:2.3:a:sap:ui5:1.60.15
-
cpe:2.3:a:sap:ui5:1.60.16
-
cpe:2.3:a:sap:ui5:1.60.17
-
cpe:2.3:a:sap:ui5:1.60.18
-
cpe:2.3:a:sap:ui5:1.60.19
-
-
cpe:2.3:a:sap:ui5:1.60.20
-
cpe:2.3:a:sap:ui5:1.60.21
-
cpe:2.3:a:sap:ui5:1.60.22
-
cpe:2.3:a:sap:ui5:1.60.23
-
cpe:2.3:a:sap:ui5:1.60.24
-
cpe:2.3:a:sap:ui5:1.60.25
-
cpe:2.3:a:sap:ui5:1.60.26
-
cpe:2.3:a:sap:ui5:1.60.27
-
cpe:2.3:a:sap:ui5:1.60.28
-
cpe:2.3:a:sap:ui5:1.60.29
-
-
cpe:2.3:a:sap:ui5:1.60.30
-
cpe:2.3:a:sap:ui5:1.60.31
-
cpe:2.3:a:sap:ui5:1.60.32
-
cpe:2.3:a:sap:ui5:1.60.33
-
-
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.71.10
-
cpe:2.3:a:sap:ui5:1.71.11
-
cpe:2.3:a:sap:ui5:1.71.12
-
cpe:2.3:a:sap:ui5:1.71.13
-
cpe:2.3:a:sap:ui5:1.71.14
-
cpe:2.3:a:sap:ui5:1.71.15
-
cpe:2.3:a:sap:ui5:1.71.16
-
cpe:2.3:a:sap:ui5:1.71.17
-
cpe:2.3:a:sap:ui5:1.71.18
-
cpe:2.3:a:sap:ui5:1.71.19
-
-
cpe:2.3:a:sap:ui5:1.71.20
-
cpe:2.3:a:sap:ui5:1.71.21
-
cpe:2.3:a:sap:ui5:1.71.22
-
cpe:2.3:a:sap:ui5:1.71.23
-
cpe:2.3:a:sap:ui5:1.71.24
-
cpe:2.3:a:sap:ui5:1.71.25
-
cpe:2.3:a:sap:ui5:1.71.26
-
cpe:2.3:a:sap:ui5:1.71.27
-
cpe:2.3:a:sap:ui5:1.71.28
-
cpe:2.3:a:sap:ui5:1.71.29
-
-
cpe:2.3:a:sap:ui5:1.71.30
-
-
-
-
-
-
-
-
-
cpe:2.3:a:sap:ui5:1.78.10
-
cpe:2.3:a:sap:ui5:1.78.11
-
cpe:2.3:a:sap:ui5:1.78.12
-
cpe:2.3:a:sap:ui5:1.78.13
-
cpe:2.3:a:sap:ui5:1.78.14
-
cpe:2.3:a:sap:ui5:1.78.15
-
cpe:2.3:a:sap:ui5:1.78.16
-
cpe:2.3:a:sap:ui5:1.78.17
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-