Vulnerability record · CVE-2021-33691 · published 15 September 2021
CVE-2021-33691: Sap netweaver development infrastructure cross-site scripting vulnerability
Sap · Netweaver Development Infrastructure
NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Service allows a threat actor to send crafted scripts to a victim. If the victim has an active session when the crafted script gets executed, the threat actor could compromise information in victims session, and gain access to some sensitive information also.
Description
NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Service allows a threat actor to send crafted scripts to a victim. If the victim has an active session when the crafted script gets executed, the threat actor could compromise information in victims session, and gain access to some sensitive information also.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://launchpad.support.sap.com/#/notes/3073450 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806 | PatchVendor Advisory |
| https://launchpad.support.sap.com/#/notes/3073450 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806 | PatchVendor Advisory |
Track CVE-2021-33691 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33691), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.