First published: Wed Nov 13 2019(Updated: )
SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Enable Now | <1908 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0385 is medium.
CVE-2019-0385 occurs due to insufficient encoding of user-controlled inputs in SAP Enable Now before version 1908, resulting in a Cross-Site Scripting (XSS) vulnerability.
The affected software for CVE-2019-0385 is SAP Enable Now before version 1908.
To fix CVE-2019-0385, update SAP Enable Now to version 1908 or later.
You can find more information about CVE-2019-0385 at the following references: [Link 1](https://launchpad.support.sap.com/#/notes/2833771), [Link 2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390).