Sensitive Information Disclosure in SAP NetWeaver AS JAVA (Enterprise Portal)

Sensitive Information Disclosure in SAP NetWeaver AS JAVA (Enterprise Portal)

CVE-2021-33687 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.

Learn more about our Web Application Penetration Testing UK.