CVE-2021-33697
No sign of exploitation. No public exploitation artifact known so far.
SAP BusinessObjects BI Platform versions 420 and 430 contain a vulnerability that allows attackers to redirect users to malicious websites without authentication. This happens through improperly handled links that can be exploited to trick users into visiting dangerous sites.
The vulnerability exists in SAPUI5 components of SAP BusinessObjects BI Platform (versions 420, 430) and enables unauthenticated attackers to perform reverse tabnabbing attacks by manipulating link handling. An attacker can craft a malicious link that, when clicked by a user, redirects to an attacker-controlled site while maintaining context that may facilitate social engineering or credential harvesting.