Insufficient Input Validation in SAPUI5 Library Affects Multiple Versions
CVE-2022-28770
6.1MEDIUM
Summary
The SAPUI5 library (vbm) for various versions contains a vulnerability stemming from insufficient input validation. This flaw allows an unauthenticated attacker to inject malicious scripts through the URL, potentially executing unwanted code within the application. Exploitation of this vulnerability can lead to unauthorized viewing or modification of sensitive information, impacting the application's confidentiality and integrity.
Affected Version(s)
SAPUI5 (vbm library) 750
SAPUI5 (vbm library) 753
SAPUI5 (vbm library) 754
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved