Medium severity6.1NVD Advisory· Published Dec 14, 2021· Updated Jun 17, 2026
CVE-2021-42063
CVE-2021-42063
Description
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:sap:knowledge_warehouse:7.30:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:sap:knowledge_warehouse:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:knowledge_warehouse:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:knowledge_warehouse:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:knowledge_warehouse:7.50:*:*:*:*:*:*:*
- (no CPE)range: 7.30, 7.31, 7.40, 7.50
- SAP SE/SAP Knowledge Warehousev5Range: < 7.30
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/166369/SAP-Knowledge-Warehouse-7.50-7.40-7.31-7.30-Cross-Site-Scripting.htmlnvdThird Party Advisory
- seclists.org/fulldisclosure/2022/Mar/32nvdMailing ListThird Party Advisory
- wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021nvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.