Advisory
A note with CVSS 3.0 for component CA-UI5-SC was released by SAP on 10.06.2025. The correction/advisory 3601169 was described with "[CVE-2025-42990] HTML Injection in Unprotected SAPUI5 applications" and affects the system type SAP UI5.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is code injection within SAP UI5.
Risk specification
Unprotected SAPUI5 applications contain a vulnerability that allows an authenticated attacker with basic privileges to inject malicious code into a web page. This may result in the redirection of users to attacker-controlled URLs, potentially facilitating phishing or other client-side attacks.Solution
The issue has been addressed by introducing a new property, disableStyleAttribute, with a default value of "false", for the sap.m.FormattedText and sap.m.FeedListItem controls. When activated, this property removes inline styles before rendering the controls in the UI, thereby mitigating the risk of malicious code injection. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Ensure input validation before storing user controlled input in the backendThe style attribute can be removed via the JavaScript function .remove attribute("style"), but this comes at the disadvantage of specific styles set by SAPUI5 not working anymore".
The advisory is valid for
- SAP_UI 750 19
- SAP_UI 754 27
- SAP_UI 755 23
- SAP_UI 756 17
- SAP_UI 757 9
- SAP_UI 758 6
- UI_700 200 11
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition