First published: Wed Jul 10 2019(Updated: )
SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Openui5 | <1.38.39 | |
Sap Openui5 | >=1.40.0<1.44.39 | |
Sap Openui5 | >=1.50.0<1.52.25 | |
Sap Openui5 | >=1.60.0<1.60.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.