CVE-2021-33667
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/07/2021
Last modified:
16/07/2021
Description
Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:businessobjects_web_intelligence:420:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:businessobjects_web_intelligence:430:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



