First published: Wed Nov 13 2019(Updated: )
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Ui | =2.0 | |
SAP UI | =7.5 | |
SAP UI | =7.51 | |
SAP UI | =7.52 | |
SAP UI | =7.53 | |
SAP UI | =7.54 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0388 is medium with a severity value of 5.3.
CVE-2019-0388 affects SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54, and SAP UI_700 version 2.0.
An attacker can exploit CVE-2019-0388 by manipulating content due to insufficient URL validation in SAP UI5 HTTP Handler.
Yes, the vulnerability has been corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54, and SAP UI_700 version 2.0.
You can find more information about CVE-2019-0388 at the following references: [link](https://launchpad.support.sap.com/#/notes/2843016) and [link](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390).