The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service when it's not.
| Software | From | Fixed in |
|---|---|---|
| sap / ui5 | 1.0.0 | 1.0.0.x |
| sap / gateway | 7.51 | 7.51.x |
| sap / gateway | 7.52 | 7.52.x |
| sap / gateway | 7.53 | 7.53.x |
| sap / gateway | 7.5 | 7.5.x |