VYPR

SAPUI5

by SAP

CVEs (4)

  • CVE-2025-42873MedDec 9, 2025
    risk 0.38cvss 5.9epss 0.00

    SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage…

  • CVE-2024-33007LowMay 14, 2024
    risk 0.23cvss 3.5epss 0.00

    PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can…

  • CVE-2025-42990LowJun 10, 2025
    risk 0.20cvss 3.0epss 0.00

    Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are…

  • CVE-2023-30743May 9, 2023
    risk 0.00cvss epss 0.00

    Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the…