CVE-2023-33991
- EPSS 0.22%
- Veröffentlicht 13.06.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:21
SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) v...
CVE-2019-0388
- EPSS 0.25%
- Veröffentlicht 13.11.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:16:46
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
CVE-2018-2424
- EPSS 0.31%
- Veröffentlicht 12.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:47
SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2....
CVE-2018-2428
- EPSS 0.21%
- Veröffentlicht 12.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:47
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7...