cvedb.io
CVE-2021-33691
MEDIUM · CVSS 6.1
EPSS exploitation probability: 0%
Published 2021-09-15T19:15:09.183 · Last modified 2026-06-17T03:55:02.560

Summary

NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Service allows a threat actor to send crafted scripts to a victim. If the victim has an active session when the crafted script gets executed, the threat actor could compromise information in victims session, and gain access to some sensitive information also.

Affected products

sap — netweaver_development_infrastructure

Does this affect you?

Add your gear to cvedb and we'll alert you only when sap ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.