Impact
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session, allowing the attacker to access sensitive session data and perform unauthorized actions. This results in a high impact on confidentiality and integrity, while availability is not affected.
Affected Systems
The vulnerability affects SAPUI5 components. No specific version or sub‑product information is provided in the available data, but the issue is documented in SAP's official patch notes.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a privileged user with content adaptation rights, followed by a user opening the compromised configuration. Although the probability of exploitation is unknown, the confirmed ability to execute arbitrary script in the victim’s session warrants timely remediation.
OpenCVE Enrichment