cbcvebase.

Sap Se Sapui5 vulnerabilities

5 known vulnerabilities affecting sap_se/sapui5.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2022-28770P4MEDIUMCVSS 6.1v750v753+3 more2022-04-12
CVE-2022-28770 [MEDIUM] CWE-79 CVE-2022-28770: Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
nvd
CVE-2023-30743P4MEDIUMCVSS 6.1vSAP_UI 750vSAP_UI 754+4 more2023-05-09
CVE-2023-30743 [MEDIUM] CWE-79 CVE-2023-30743: Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the absence of URL validation by the application, the vulnerability could lead to th
nvd
CVE-2019-0281P4MEDIUMCVSS 6.1v1.38.39v1.44.39+3 more2019-07-10
CVE-2019-0281 [MEDIUM] CWE-79 CVE-2019-0281: SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficien SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2026-34258P4MEDIUMCVSS 4.7vSAPUI5 1.108v1.120+5 more2026-05-12
CVE-2026-34258 [MEDIUM] CWE-451 CVE-2026-34258: SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the S SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low impact on confidentiality with no effect on the int
nvd
CVE-2024-33007P4LOWCVSS 3.5v754v755+3 more2024-05-14
CVE-2024-33007 [LOW] CWE-79 CVE-2024-33007: PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedde PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.
nvd
Sap Se Sapui5 vulnerabilities | cvebase