CVE-2019-0368: XSS
SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0368?
CVE-2019-0368 is rated as a medium severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2019-0368?
To address CVE-2019-0368, ensure that you apply the latest security patches provided by SAP for your affected CRM version.
What versions are affected by CVE-2019-0368?
CVE-2019-0368 affects SAP Customer Relationship Management versions before 1.0 and 2.0, as well as BBPCRM versions before 7.0, 7.01, 7.02, 7.12, 7.13, and 7.14.
What type of vulnerability is CVE-2019-0368?
CVE-2019-0368 is a Cross-Site Scripting (XSS) vulnerability caused by inadequate encoding of user-controlled inputs in the mail client.
Can CVE-2019-0368 lead to unauthorized access?
Yes, CVE-2019-0368 can potentially lead to unauthorized access or data manipulation through malicious scripts executed by unsuspecting users.