SAP security note 2621121, "CVE-2018-2428 Information Disclosure in UI5 Handler", is a note released on June 12, 2018. Below are the symptom, CVSS score, SAP recommended solution, affected software components and references.
Description
Symptom
Under certain conditions, the UI5 Handler allows an attacker to access information that should otherwise be restricted.
Solution
Apply the correction instructions or install the relevant support packages to prevent the UI5 Handler from leaking unnecessary information.
CVSS
Score 5.3 / 10
References
Affected components
- UI_INFRA
- SAP_UI
- UI_700
Full note on SAP: SAP Support Launchpad note 2621121
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



