CVE-2019-0277: XEE

Published Mar 12, 2019
·
Updated

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).

Affected Software

1 affected component
SAP HANA Extended Application Services=1.0

Event History

Mar 12, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2019-0277?

CVE-2019-0277 is classified as a high severity vulnerability due to the risk of XML External Entity attacks.

2

How do I fix CVE-2019-0277?

To fix CVE-2019-0277, ensure that your SAP HANA extended application services are updated to the latest version that addresses this XML validation issue.

3

Who is impacted by CVE-2019-0277?

Users and developers with privileges to the SAP space in SAP HANA extended application services version 1.0 are primarily impacted by CVE-2019-0277.

4

What does CVE-2019-0277 exploit?

CVE-2019-0277 exploits insufficient validation of XML documents, allowing for potential XML External Entity attacks.

5

Is there a workaround for CVE-2019-0277?

Until a patch can be applied, it is advisable to limit access and permissions for authenticated developers to mitigate the risks of CVE-2019-0277.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203