Vulnerability Details CVE-2021-33703
Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker can craft a malicious link and send it to a victim. A successful attack results in Reflected Cross-Site Scripting (XSS) vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.3%
CVSS Severity
CVSS v3 Score 8.3
CVSS v2 Score 2.6
Products affected by CVE-2021-33703
-
cpe:2.3:a:sap:netweaver_enterprise_portal:7.30
-
cpe:2.3:a:sap:netweaver_enterprise_portal:7.31
-
cpe:2.3:a:sap:netweaver_enterprise_portal:7.40
-
cpe:2.3:a:sap:netweaver_enterprise_portal:7.50