SAPUI5 Search UI URL Parameter Manipulation Vulnerability

Vulnerability

A vulnerability in SAPUI5 Search UI allows an unauthenticated attacker to alter specific URL parameters to inject malicious content. This exploitation could mislead users into clicking on links that lead to attacker-controlled pages, posing a low risk to confidentiality but no impact on the application's integrity or availability.

Impact

Exploitation of this vulnerability could lead to phishing attacks, where users are tricked into visiting malicious websites controlled by the attacker.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.

Added: May 12, 2026, 3:27 AM
Updated: May 12, 2026, 3:27 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
1.0
exploitability
4.2
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.