Medium severity5.4NVD Advisory· Published Sep 15, 2021· Updated Jun 17, 2026
CVE-2021-33696
CVE-2021-33696
Description
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.
Affected products
4cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:businessobjects_business_intelligence:420:*:*:*:*:*:*:*
- cpe:2.3:a:sap:businessobjects_business_intelligence:430:*:*:*:*:*:*:*
- Range: 420, 430
- SAP SE/SAP BusinessObjects Business Intelligence Platform (Crystal Report)v5Range: < 420
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdPatchVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.