CVE-2021-33687 PUBLISHED CVSS 4.5 MEDIUM

SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.

EPSS 0.72% · 72.4th percentile

Risk Scores

CVSS v3.0
4.5
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.72%
72.4th percentile

Affected Products

VendorProductVersions
sapnetweaver_application_server_java7.50, 7.10, 7.20
SAP SESAP NetWeaver AS JAVA (Enterprise Portal)< 7.30, < 7.31, < 7.40

Timeline

References

Open in Interactive Console →