CVE-2019-0298: XSS
Published May 14, 2019
·Updated
SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Fixed in the following components SAP-CRMJAV SAP-CRMWEB SAP-SHRWEB SAP-SHRJAV SAP-CRMAPP SAP-SHRAPP, versions 7.30, 7.31, 7.32, 7.33, 7.54.
Affected Software
5 affected components
SAP E-Commerce=7.30
SAP E-Commerce=7.31
SAP E-Commerce=7.32
SAP E-Commerce=7.33
SAP E-Commerce=7.54
Event History
May 14, 2019
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0298?
CVE-2019-0298 has a moderate severity rating due to its potential for Cross-Site Scripting exploitation.
2
How do I fix CVE-2019-0298?
To fix CVE-2019-0298, update the affected SAP E-Commerce components to versions 7.30, 7.31, 7.32, 7.33, or 7.54.
3
Which software versions are affected by CVE-2019-0298?
CVE-2019-0298 affects SAP E-Commerce versions 7.30, 7.31, 7.32, 7.33, and 7.54.
4
What type of vulnerability is CVE-2019-0298?
CVE-2019-0298 is a Cross-Site Scripting (XSS) vulnerability.
5
Who can be impacted by CVE-2019-0298?
Users interacting with vulnerable SAP E-Commerce applications may be impacted by CVE-2019-0298.