CVE Published: 09/02/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: sap |
Vendor: SAP SE |
Product: SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) Status : PUBLISHED
CVE-2021-21444 Description
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.