PT-2019-4590 · Sap · Openui5+1

Published

2019-07-09

·

Updated

2019-07-18

·

CVE-2019-0281

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAPUI5 versions prior to 1.38.39 SAPUI5 versions prior to 1.44.39 SAPUI5 versions prior to 1.52.25 SAPUI5 versions prior to 1.60.6 SAPUI5 versions prior to 1.63.0 OpenUI5 versions prior to 1.38.39 OpenUI5 versions prior to 1.44.39 OpenUI5 versions prior to 1.52.25 OpenUI5 versions prior to 1.60.6 OpenUI5 versions prior to 1.63.0
Description The issue arises from insufficient encoding of user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations For SAPUI5 versions prior to 1.38.39, update to version 1.38.39 or later. For SAPUI5 versions prior to 1.44.39, update to version 1.44.39 or later. For SAPUI5 versions prior to 1.52.25, update to version 1.52.25 or later. For SAPUI5 versions prior to 1.60.6, update to version 1.60.6 or later. For SAPUI5 versions prior to 1.63.0, update to version 1.63.0 or later. For OpenUI5 versions prior to 1.38.39, update to version 1.38.39 or later. For OpenUI5 versions prior to 1.44.39, update to version 1.44.39 or later. For OpenUI5 versions prior to 1.52.25, update to version 1.52.25 or later. For OpenUI5 versions prior to 1.60.6, update to version 1.60.6 or later. For OpenUI5 versions prior to 1.63.0, update to version 1.63.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00650
CVE-2019-0281

Affected Products

Openui5
Sapui5