Vulnerability Description
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Ui5 | < 1.38.49 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3014303Permissions RequiredThird Party Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3014303Permissions RequiredThird Party Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543Vendor Advisory
FAQ
What is CVE-2021-21476?
CVE-2021-21476 is a vulnerability with a CVSS score of 6.1 (MEDIUM). SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabi...
How severe is CVE-2021-21476?
CVE-2021-21476 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21476?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Ui5.