← Back

CVE-2023-33991

nvd nist
Published: Jun 13, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
Exploitability: 2.3 / Impact: 5.3
Source: NVD

Description

SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user level access can cause high impact on confidentiality, modify some information and can cause unavailability of the application at user level.

Affected (6)

Products: Sap: Ui
1 product
Ui
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 700
Version 750
Version 754
Version 755
Version 756
Version 757

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.