Vulnerability Description
SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-based attacks in applications that accept attacker-controlled XML configuration files. This occurs as logging service does not disable XML external entities when parsing configuration files and a successful exploit would result in limited impact on integrity and availability of the application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Enterprise Performance Management | 2.8 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3000291Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3000291Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476Vendor Advisory
FAQ
What is CVE-2021-21470?
CVE-2021-21470 is a vulnerability with a CVSS score of 4.4 (MEDIUM). SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which ...
How severe is CVE-2021-21470?
CVE-2021-21470 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21470?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Enterprise Performance Management.