CVE-2019-0238: XSS
Published Jan 8, 2019
·Updated
SAP Commerce (previously known as SAP Hybris Commerce), before version 6.7, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
1 affected component
SAP Hybris<6.7
Event History
Jan 8, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0238?
CVE-2019-0238 has been assigned a medium severity rating due to the potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2019-0238?
To fix CVE-2019-0238, upgrade your SAP Commerce system to version 6.7 or later.
3
What causes CVE-2019-0238?
CVE-2019-0238 is caused by insufficient encoding of user-controlled inputs in SAP Commerce.
4
Who is affected by CVE-2019-0238?
CVE-2019-0238 affects users of SAP Commerce prior to version 6.7.
5
What kind of attacks can be executed through CVE-2019-0238?
CVE-2019-0238 can be exploited to perform Cross-Site Scripting attacks, allowing malicious scripts to be executed in users' browsers.