First published: Tue Jan 08 2019(Updated: )
SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Customer Relationship Management Webclient Ui | =7.31 | |
Sap Customer Relationship Management Webclient Ui | =7.46 | |
Sap Customer Relationship Management Webclient Ui | =7.47 | |
Sap Customer Relationship Management Webclient Ui | =7.48 | |
Sap Customer Relationship Management Webclient Ui | =8.00 | |
Sap Customer Relationship Management Webclient Ui | =8.01 | |
Sap S4fnd | =1.02 | |
Sap Sapscore | =1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0244 is a Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI.
The severity of CVE-2019-0244 is medium with a CVSS score of 5.4.
SAP CRM WebClient UI versions 7.31, 7.46, 7.47, 7.48, 8.0, and 8.01 are affected by CVE-2019-0244.
To fix CVE-2019-0244, update SAPSCORE to version 1.12, S4FND to version 1.02, and WEBCUIF to versions 7.31, 7.46, 7.47, 7.48, 8.0, or 8.01.
You can find more information about CVE-2019-0244 at the following references: [1] [2] [3].