Vulnerability Description
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Businessobjects Business Intelligence | 410 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2935791Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2935791Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543Vendor Advisory
FAQ
What is CVE-2021-21444?
CVE-2021-21444 is a vulnerability with a CVSS score of 6.1 (MEDIUM). SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could...
How severe is CVE-2021-21444?
CVE-2021-21444 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21444?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Businessobjects Business Intelligence.