SAPUI5 Applications Cross-Site Scripting Vulnerability Allowing URL Redirection

Vulnerability

A cross-site scripting vulnerability has been identified in unprotected SAPUI5 applications. This issue allows an attacker with basic privileges to inject malicious HTML into a webpage, potentially redirecting users to an attacker-controlled URL. The vulnerability could compromise the integrity of the application, although it does not affect confidentiality or availability.

Impact

Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.

Remediation

Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP for Me platform. This vulnerability will also be addressed in the upcoming SAP Security Patch Day.

Added: Jun 10, 2025, 1:22 AM
Updated: Jun 10, 2025, 1:22 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
0.6
exploitability
3.0
remediation
6.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.