CVE-2019-0254: XSS
SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is SAP Disclosure Management?
SAP Disclosure Management is a software solution developed by SAP that helps organizations streamline the disclosure process for financial reporting and compliance requirements.
What is the severity of CVE-2019-0254?
The severity of CVE-2019-0254 is medium with a CVSS score of 5.4.
What is Cross-Site Scripting (XSS) vulnerability?
Cross-Site Scripting (XSS) vulnerability is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
How does CVE-2019-0254 affect SAP Disclosure Management?
CVE-2019-0254 affects SAP Disclosure Management versions before 10.1 Stack 1301 by not sufficiently encoding user-controlled inputs, which leads to a Cross-Site Scripting (XSS) vulnerability.
How can I fix CVE-2019-0254?
To fix CVE-2019-0254, you should upgrade SAP Disclosure Management to version 10.1 Stack 1301 or later, where the vulnerability has been addressed.