PT-2023-3746 · Sap · Sap Ui5 Variant Management
Published
2023-06-13
·
Updated
2023-06-20
·
CVE-2023-33991
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAP UI5 Variant Management versions SAP UI 750 through SAP UI 757, UI 700 200
Description
The issue is related to insufficient encoding of user-controlled inputs when reading data from the server, resulting in a Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user-level access can cause high impact on confidentiality, modify some information, and can cause unavailability of the application at the user level.
Recommendations
For SAP UI5 Variant Management versions SAP UI 750 through SAP UI 757, and UI 700 200, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Ui5 Variant Management