NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Service allows a threat actor to send crafted scripts to a victim. If the victim has an active session when the crafted script gets executed, the threat actor could compromise information in victims session, and gain access to some sensitive information also.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2021-09-15T18:01:48
Updated: 2024-08-03T23:58:22.507Z
Reserved: 2021-05-28T00:00:00
Link: CVE-2021-33691
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-15T19:15:09.183
Modified: 2024-11-21T06:09:22.697
Link: CVE-2021-33691
Redhat
No data.