Vulnerability: - Type: Cross-Site Scripting (XSS) - Impact on Business: - Dependent on victim's privileges, allows session hijacking, cross-site requests, and open redirects. - Affected Components: - SAP_UI 753, 754, 755, 756, and SAP_BASIS 787. - CVSS v3 score: 8.2 - CVE ID: CVE-2022-26101 - Risk Level: High Solution: - SAP has released SAP Note 3149805 with patched versions of the affected components. - Patches available here. Timeline: - 01/28/2022: Onapsis sends details to SAP. - 06/21/2022: Advisory published. References: - Onapsis blogpost link - CVE Mitre link - Vendor Patch link