CVE Database
/

CVE-2022-28770

Back to search

CVE-2022-28770

Published: Apr 12, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

VendorProductVersions

SAP SE

SAPUI5 (vbm library)

affected
750
affected
753
affected
754
affected
755
affected
756

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now