PT-2022-15498 · Sap · Sap Ui5+1
Published
2022-01-14
·
Updated
2026-02-24
·
CVE-2022-22529
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Enterprise Threat Detection (ETD) version 2.0
Description
The issue arises from insufficient encoding of user-controlled inputs, potentially leading to an unauthorized attacker exploiting an XSS vulnerability. However, the UIs in ETD utilize SAP UI5 standard controls, which provide automated output encoding. This encoding prevents stored malicious user input from being executed when reflected in the UI.
Recommendations
For SAP Enterprise Threat Detection (ETD) version 2.0, consider implementing additional encoding measures for user-controlled inputs to prevent potential XSS exploitation. As a temporary workaround, ensure that the automated output encoding provided by the SAP UI5 framework is properly configured and utilized to minimize the risk of stored malicious user input being executed.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Enterprise Threat Detection
Sap Ui5