SAP security note 2965154, "[CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control. This payload can be executed by users who view the relevant application content, leading to Stored Cross-Site Scripting (XSS).
Impacts of XSS Vulnerability:
- Content Modification: Non-permanently deface or modify displayed content from a website.
- Data Theft: Steal authentication information of the user, such as data relating to their current session.
- User Impersonation: Impersonate the user and access all information with the same rights as the target user.
Solution
User inputs are now encoded for the affected workflows. This issue is fixed in the patches listed in the Support Packages & Patches section below. The section will be updated with the relevant patch levels once they are released.
For the Business Intelligence Platform maintenance schedule and strategy, refer to the Knowledge Base Article 2144559 in the References section.
Reason and prerequisites
User input was not correctly validated in a control, allowing malicious scripts to be injected and executed.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Affected components
- ENTERPRISE: Versions 410, 420
Full note on SAP: SAP Support Launchpad note 2965154
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




