SAPUI5
cpe:2.3:a:sap:ui5:*:*:*:*:*:*:*
A cross-site scripting vulnerability has been identified in unprotected SAPUI5 applications. This issue allows an attacker with basic privileges to inject malicious HTML into a webpage, potentially redirecting users to an attacker-controlled URL. The vulnerability could compromise the integrity of the application, although it does not affect confidentiality or availability.
Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.
Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP for Me platform. This vulnerability will also be addressed in the upcoming SAP Security Patch Day.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.