CVE-2022-28770: XSS
Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28770?
CVE-2022-28770 is classified as a moderate severity vulnerability due to its potential to impact confidentiality and integrity.
How do I fix CVE-2022-28770?
To fix CVE-2022-28770, update the SAPUI5 library to a version that addresses input validation issues.
Who is affected by CVE-2022-28770?
CVE-2022-28770 affects users of SAPUI5 library versions 750, 753, 754, 755, and 756.
What are the potential impacts of CVE-2022-28770?
The potential impacts of CVE-2022-28770 include unauthorized script execution, leading to information disclosure or modification.
Is CVE-2022-28770 a zero-day vulnerability?
CVE-2022-28770 is not a zero-day vulnerability, but it can be exploited if the affected versions are not updated.