CVE-2019-0370

6.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 October 2019

Summary

Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.

Affected Version(s)

SAP Financial Consolidation < 10.0 < 10.0

SAP Financial Consolidation < 10.1 < 10.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.