Vulnerability Description
Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the usage of ActiveX in the application, the attacker can further execute operating system level commands in the chat recipient's scope. This could lead to a complete compromise of their confidentiality, integrity, and could temporarily impact their availability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Contact Center | 700 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3073891Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3073891Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
FAQ
What is CVE-2021-33672?
CVE-2021-33672 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipien...
How severe is CVE-2021-33672?
CVE-2021-33672 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-33672?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Contact Center.