Insufficient Input Validation in SAPUI5 Library Affects Multiple Versions
CVE-2022-28770

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 April 2022

Summary

The SAPUI5 library (vbm) for various versions contains a vulnerability stemming from insufficient input validation. This flaw allows an unauthenticated attacker to inject malicious scripts through the URL, potentially executing unwanted code within the application. Exploitation of this vulnerability can lead to unauthorized viewing or modification of sensitive information, impacting the application's confidentiality and integrity.

Affected Version(s)

SAPUI5 (vbm library) 750

SAPUI5 (vbm library) 753

SAPUI5 (vbm library) 754

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.