PT-2023-22947 · Sap · Sapui5

Published

2023-05-09

·

Updated

2023-06-15

·

CVE-2023-30743

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAPUI5 versions SAP UI 750, SAP UI 754, SAP UI 755, SAP UI 756, SAP UI 757, UI 700 200
Description The issue arises from improper neutralization of input in SAPUI5, allowing the injection of untrusted CSS through the sap.m.FormattedText SAPUI5 control. This can block user interaction with the application. Additionally, the lack of URL validation by the application could enable an attacker to read or modify user information through a phishing attack.
Recommendations For SAPUI5 versions SAP UI 750, SAP UI 754, SAP UI 755, SAP UI 756, SAP UI 757, UI 700 200, consider disabling the sap.m.FormattedText SAPUI5 control until a patch is available to prevent the injection of untrusted CSS. Restrict access to the vulnerable SAPUI5 control to minimize the risk of exploitation. Avoid using the sap.m.FormattedText control in applications where URL validation is not properly implemented until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-30743

Affected Products

Sapui5