CVE-2019-0277: XEE
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0277?
CVE-2019-0277 is classified as a high severity vulnerability due to the risk of XML External Entity attacks.
How do I fix CVE-2019-0277?
To fix CVE-2019-0277, ensure that your SAP HANA extended application services are updated to the latest version that addresses this XML validation issue.
Who is impacted by CVE-2019-0277?
Users and developers with privileges to the SAP space in SAP HANA extended application services version 1.0 are primarily impacted by CVE-2019-0277.
What does CVE-2019-0277 exploit?
CVE-2019-0277 exploits insufficient validation of XML documents, allowing for potential XML External Entity attacks.
Is there a workaround for CVE-2019-0277?
Until a patch can be applied, it is advisable to limit access and permissions for authenticated developers to mitigate the risks of CVE-2019-0277.