MEDIUM🇵🇱 Wersja polska

CVE-2021-33694

CVSS 4.8v3.1pub. 2021-09-15upd. 2024-11-21

SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
  • Sap Cloud Connector

    APP
    Sap
    2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2021-33695CRITICAL9.1PL ✓same product

SAP Cloud Connector: niewystarczająca walidacja certyfikatu TLS

CVE-2019-0247CRITICAL9.8PL ✓same product

SAP Cloud Connector – wstrzyknięcie kodu (code injection) przed wersją 2.11.3

CVE-2019-0246CRITICAL9.8PL ✓same product

SAP Cloud Connector: brak uwierzytelnienia dla krytycznych funkcji

CVE-2024-25642HIGH7.4same product

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the g...

CVE-2021-33692HIGH7.5same product

SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked ...