Medium severity4.3NVD Advisory· Published Jul 14, 2021· Updated Jun 17, 2026
CVE-2021-33667
CVE-2021-33667
Description
Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.
Affected products
4cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_web_intelligence:430:*:*:*:*:*:*:*
- Range: 420, 430
- SAP SE/SAP Business Objects Web Intelligence (BI Launchpad)v5Range: < 420
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.