CVE-2019-0321: XSS
Published Jul 10, 2019
·Updated
ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
3 affected components
SAP NetWeaver Application Server ABAP=7.31
SAP NetWeaver AS ABAP=7.4
SAP NetWeaver AS ABAP=7.5
Event History
Jul 10, 2019
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-0321.
2
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium.
3
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-79.
4
Which versions of ABAP Server and ABAP Platform are affected?
Versions 7.31, 7.4, and 7.5 of ABAP Server and ABAP Platform (SAP Basis) are affected.
5
How can this vulnerability be exploited?
This vulnerability can be exploited through Cross-Site Scripting (XSS).