Impact
SAP UI5 does not properly verify parent frame origins against its allowlist, allowing an unauthenticated attacker to host a malicious page that embeds UI5 content with deceptive framing. When an authenticated user visits that page and interacts with the UI, the attacker can trick the user into completing unintended actions, subtly affecting data integrity. The vulnerability has no effect on confidentiality or availability and is categorized as CWE-1289.
Affected Systems
SAP UI5 for the Frame Options Allowlist component, provided by SAP SE. Versions affected are not explicitly listed, implying any release that includes the allowlist configuration for frame options may be vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places this flaw in the moderate category, while the EPSS score is unavailable, so the exact exploitation probability cannot be quantified. This vulnerability is not present in the CISA KEV catalog, indicating no known widespread exploitation at this time. The likely attack vector involves a malicious site hosting the UI5 framework without proper origin checks; the attacker needs only the victim to visit this site and interact, with no privileged access required. Consequently the risk is moderate but the potential damage remains low, emphasizing the need to remediate through patching or configurational changes.
OpenCVE Enrichment