VDB
CVE-2021-33672
CVE-2021-33672
PUBLISHED
CVSS 9.600000381469727 CRITICAL
Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the usage of ActiveX in the application, the attacker can further execute operating system level commands in the chat recipient's scope. This could lead to a complete compromise of their confidentiality, integrity, and could temporarily impact their availability.
EPSS 0.27% · 50.6th percentile
Risk Scores
CVSS 3.0
9.600000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
EPSS Score
0.27%
50.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP SE | SAP Contact Center | < 700 |
| sap | contact_center | 700 |
Timeline
- Sep 14, 2021 CVE Published
- Sep 15, 2021 EPSS Score
- Nov 11, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 8, 2022 EPSS Score
- Mar 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jun 29, 2022 EPSS Score
- Aug 27, 2022 EPSS Score
- Oct 23, 2022 EPSS Score
- Dec 20, 2022 EPSS Score