CVE-2021-21444

Publication date

2021-02-09 20:44:22

Family

sap

State

PUBLISHED

Description

SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.