SAP Knowledge Base Article - Preview

3502230 - Polyfilling in SAPUI5 Library concerns tied to polyfills(.)io/cdn.polyfills(.)io attack

Symptom

  • An advisory regarding the Polyfills Supply Chain Attack where in a “polyfills(.)io/cdn.polyfills(.)io” domain has been acquired by a Chinese firm which has done unauthorized modifications to the script to redirect the users to malicious sites.

  • A Polyfill is code, such as JavaScript, that adds modern functionality to older browsers that do not usually support it.

  • It is advised by the security firms to identify and remove “polyfills” if used in any applications.


Read more...

Environment

S/HANA 2020 and others

Product

SAP S/4HANA 2020

Keywords

"polyfill.io","polyfill attack","polyfill attack supply chain","polyfill.io","SAPUI5 polyfill.io","CVE-2024-38526" , KBA , CA-UI5-COR , Core and Runtime , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.