VYPR
Medium severity6.1NVD Advisory· Published Apr 12, 2022· Updated Jun 17, 2026

CVE-2022-28770

CVE-2022-28770

Description

Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

Affected products

9
  • cpe:2.3:a:sap:sapui5_library:200:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:sap:sapui5_library:200:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sapui5_library:750:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sapui5_library:753:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sapui5_library:754:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sapui5_library:755:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sapui5_library:756:*:*:*:*:*:*:*
  • Range: 750, 753, 754, 755, 75
  • Range: 750, 753, 754, 755, 75
  • SAP SE/SAPUI5 (vbm library)v5
    Range: 750

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.