First published: Fri Feb 15 2019(Updated: )
SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Disclosure Management | <10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
SAP Disclosure Management is a software solution developed by SAP that helps organizations streamline the disclosure process for financial reporting and compliance requirements.
The severity of CVE-2019-0254 is medium with a CVSS score of 5.4.
Cross-Site Scripting (XSS) vulnerability is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
CVE-2019-0254 affects SAP Disclosure Management versions before 10.1 Stack 1301 by not sufficiently encoding user-controlled inputs, which leads to a Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2019-0254, you should upgrade SAP Disclosure Management to version 10.1 Stack 1301 or later, where the vulnerability has been addressed.