CVE-2021-21491
CVE-2021-21491
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.7EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Mar 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Affected products
SAP SE · SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →