First published: Tue Sep 10 2019(Updated: )
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Supplier Relationship Management | =3.73 | |
SAP Supplier Relationship Management | =7.31 | |
SAP Supplier Relationship Management | =7.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0361 is medium.
The CVE-2019-0361 vulnerability affects SAP Supplier Relationship Management (SRM) versions 3.73, 7.31, and 7.32.
The CVE-2019-0361 vulnerability allows for Cross-Site Scripting (XSS) attacks.
To fix the CVE-2019-0361 vulnerability in SAP Supplier Relationship Management (SRM), update to versions 3.73 PL22, 7.31 PL23, or 7.32 PL09.
More information about the CVE-2019-0361 vulnerability can be found at the following references: [1] [2].