Missing XML Validation Vulnerability in SAP Enable Now
CVE-2019-0340

5.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 August 2019

Summary

The XML parser utilized in SAP Enable Now prior to version 1902 is not properly hardened, creating a potential for a Missing XML Validation vulnerability. This flaw allows attackers to exploit the file upload functionalities located at various points within the system, potentially enabling unauthorized access to local files through XML External Entity (XXE) attacks. As a result, sensitive information may be exposed if adequate security measures are not implemented.

Affected Version(s)

SAP Enable Now < 1902

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.