- Description
- Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.
- Source
- cna@sap.com
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:infrastructure:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "323BCB98-A9B2-45B7-90B7-6ED04EA7A08C"
},
{
"criteria": "cpe:2.3:a:sap:ui:2.0:*:*:*:*:netweaver_7.0:*:*",
"vulnerable": true,
"matchCriteriaId": "BAC1FC47-D27B-4D31-B0CB-84CB75B9B314"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4846F44-7C76-452A-BF32-0EA2BA92684E"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DD71946-CF00-420E-A6BE-4E0A378AC6C9"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2AE480CB-D830-42D5-B297-3D5874AEFA36"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.52:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "830F67FF-0DEA-4B07-A3E0-CDCD01888DED"
}
],
"operator": "OR"
}
]
}
]