VDB
CVE-2021-21447
CVE-2021-21447
PUBLISHED
CVSS 5.400000095367432 MEDIUM
SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.
EPSS 0.26% · 49.7th percentile
Risk Scores
CVSS v3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.26%
49.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP SE | SAP BusinessObjects Business Intelligence platform (Web Intelligence HTML interface) | < 410, < 420 |
| sap | businessobjects_business_intelligence | 410, 420 |
Timeline
- Jan 12, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 27, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 5, 2022 EPSS Score