SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have control over kind or degree.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-14348 SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have control over kind or degree.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-03T21:26:10.336Z

Reserved: 2021-02-23T00:00:00

Link: CVE-2021-27601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-13T19:15:15.257

Modified: 2024-11-21T05:58:16.440

Link: CVE-2021-27601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.