VYPR
Medium severity4.3NVD Advisory· Published Jul 14, 2021· Updated Jun 17, 2026

CVE-2021-33667

CVE-2021-33667

Description

Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.

Affected products

4
  • cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:businessobjects_web_intelligence:430:*:*:*:*:*:*:*
  • SAP SE/SAP Business Objects Web Intelligence (BI Launchpad)v5
    Range: < 420

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.