CVE-2019-0244: XSS
Published Jan 8, 2019
·Updated
SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
8 affected components
SAP Customer Relationship Management Webclient Ui=7.31
SAP Customer Relationship Management Webclient Ui=7.46
SAP Customer Relationship Management Webclient Ui=7.47
SAP Customer Relationship Management Webclient Ui=7.48
SAP Customer Relationship Management Webclient Ui=8.00
SAP Customer Relationship Management Webclient Ui=8.01
SAP S4FND=1.02
SAP SAPSCORE=1.12
Event History
Jan 8, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-0244?
CVE-2019-0244 is a Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI.
2
How severe is CVE-2019-0244?
The severity of CVE-2019-0244 is medium with a CVSS score of 5.4.
3
Which software versions are affected by CVE-2019-0244?
SAP CRM WebClient UI versions 7.31, 7.46, 7.47, 7.48, 8.0, and 8.01 are affected by CVE-2019-0244.
4
How can I fix CVE-2019-0244?
To fix CVE-2019-0244, update SAPSCORE to version 1.12, S4FND to version 1.02, and WEBCUIF to versions 7.31, 7.46, 7.47, 7.48, 8.0, or 8.01.
5
Where can I find more information about CVE-2019-0244?
You can find more information about CVE-2019-0244 at the following references: [1] [2] [3].