- Description
- SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
- Source
- cna@sap.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
- nvd@nist.gov
- CWE-290
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:ui:2.0:*:*:*:*:netweaver_7.0:*:*",
"vulnerable": true,
"matchCriteriaId": "BAC1FC47-D27B-4D31-B0CB-84CB75B9B314"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DD71946-CF00-420E-A6BE-4E0A378AC6C9"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2AE480CB-D830-42D5-B297-3D5874AEFA36"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.52:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "830F67FF-0DEA-4B07-A3E0-CDCD01888DED"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.53:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E32872FA-4C9E-4F82-BFEF-B583C2AE36BC"
},
{
"criteria": "cpe:2.3:a:sap:ui:7.54:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A48C9F7E-AB1D-4B39-83E2-97A25F71FF11"
}
],
"operator": "OR"
}
]
}
]