Symptom
-
An advisory regarding the Polyfills Supply Chain Attack where in a “polyfills(.)io/cdn.polyfills(.)io” domain has been acquired by a Chinese firm which has done unauthorized modifications to the script to redirect the users to malicious sites.
-
A Polyfill is code, such as JavaScript, that adds modern functionality to older browsers that do not usually support it.
-
It is advised by the security firms to identify and remove “polyfills” if used in any applications.
Read more...
Environment
S/HANA 2020 and others
Product
Keywords
"polyfill.io","polyfill attack","polyfill attack supply chain","polyfill.io","SAPUI5 polyfill.io","CVE-2024-38526" , KBA , CA-UI5-COR , Core and Runtime , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview