CyberRota Analysis
AI-GeneratedSAP UI5 is vulnerable due to inadequate validation of the parent frame's origin against the configured allowlist, allowing an unauthenticated attacker to host a malicious page. If an authenticated user interacts with this page, the attacker could manipulate the user into executing unintended actions, potentially compromising data integrity. Organizations using SAP UI5 should prioritize addressing this vulnerability to mitigate risks associated with user interaction and potential integrity issues.
Original NVD Description
SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.