The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service when its not.
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gateway | Sap | 7.5 (including) | 7.5 (including) |
Gateway | Sap | 7.51 (including) | 7.51 (including) |
Gateway | Sap | 7.52 (including) | 7.52 (including) |
Gateway | Sap | 7.53 (including) | 7.53 (including) |
Ui5 | Sap | 1.0.0 (including) | 1.0.0 (including) |