CVE-2019-0385: XSS
Published Nov 13, 2019
·Updated
SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
1 affected component
SAP Enable Now<1908
Event History
Nov 13, 2019
CVE Published
via MITRE·09:57 PM
Data Sourced
via MITRE·09:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0385?
The severity of CVE-2019-0385 is medium.
2
How does CVE-2019-0385 occur?
CVE-2019-0385 occurs due to insufficient encoding of user-controlled inputs in SAP Enable Now before version 1908, resulting in a Cross-Site Scripting (XSS) vulnerability.
3
What is the affected software for CVE-2019-0385?
The affected software for CVE-2019-0385 is SAP Enable Now before version 1908.
4
How can I fix CVE-2019-0385?
To fix CVE-2019-0385, update SAP Enable Now to version 1908 or later.
5
Where can I find more information about CVE-2019-0385?
You can find more information about CVE-2019-0385 at the following references: [Link 1](https://launchpad.support.sap.com/#/notes/2833771), [Link 2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390).