Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2021-21447 Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), SAP security note 2965154

SAP Note 2965154

SAP security note 2965154, "[CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control. This payload can be executed by users who view the relevant application content, leading to Stored Cross-Site Scripting (XSS).

Impacts of XSS Vulnerability:

  • Content Modification: Non-permanently deface or modify displayed content from a website.
  • Data Theft: Steal authentication information of the user, such as data relating to their current session.
  • User Impersonation: Impersonate the user and access all information with the same rights as the target user.

Solution

User inputs are now encoded for the affected workflows. This issue is fixed in the patches listed in the Support Packages & Patches section below. The section will be updated with the relevant patch levels once they are released.

For the Business Intelligence Platform maintenance schedule and strategy, refer to the Knowledge Base Article 2144559 in the References section.

Reason and prerequisites

User input was not correctly validated in a control, allowing malicious scripts to be injected and executed.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • ENTERPRISE: Versions 410, 420

Full note on SAP: SAP Support Launchpad note 2965154

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.