Description
SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user level access can cause high impact on confidentiality, modify some information and can cause unavailability of the application at user level.
References (2)
Core 2
Core References
Permissions Required
https://launchpad.support.sap.com/#/notes/3324285
Scores
CVSS v3
8.2
EPSS
0.0027
EPSS Percentile
50.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (6)
sap/ui
700
sap/ui
750
sap/ui
754
sap/ui
755
sap/ui
756
sap/ui
757
Published
Jun 13, 2023
Tracked Since
Feb 18, 2026