CVE detail
CVE-2021-21490 — CVE-2021-21490
Published 2021-06-09 · Modified 2026-06-17 · Vendor sap · Product netweaver_application_server_abap · Source nvd
MEDIUM
severity
CVSS-derived band
0.0059
EPSS probability
exploitation probability, 30d
45.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References