Lucene search

K
cve[email protected]CVE-2023-33991
HistoryJun 13, 2023 - 3:15 a.m.

CVE-2023-33991

2023-06-1303:15:09
CWE-79
web.nvd.nist.gov
17
sap
ui5
variant management
sap_ui
xss
stored xss
vulnerability
nvd
cve-2023-33991

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.4%

SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user level access can cause high impact on confidentiality, modify some information and can cause unavailability of the application at user level.

Affected configurations

NVD
Node
sapuiMatch700
OR
sapuiMatch750
OR
sapuiMatch754
OR
sapuiMatch755
OR
sapuiMatch756
OR
sapuiMatch757

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP UI5 Variant Management",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "SAP_UI 750"
      },
      {
        "status": "affected",
        "version": "SAP_UI 754"
      },
      {
        "status": "affected",
        "version": "SAP_UI 755"
      },
      {
        "status": "affected",
        "version": "SAP_UI 756"
      },
      {
        "status": "affected",
        "version": "SAP_UI 757"
      },
      {
        "status": "affected",
        "version": "UI_700 200"
      }
    ]
  }
]

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.4%

Related for CVE-2023-33991