CVE-2019-0316
Summary
| CVE | CVE-2019-0316 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-14 19:29:00 UTC |
| Updated | 2020-02-10 21:48:00 UTC |
| Description | SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the victim is tricked to click on those malicious links, resulting in reflected Cross Site Scripting vulnerability. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Process Integration | 7.10 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.11 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.20 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.30 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.31 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.40 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.50 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.10 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.11 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.20 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.30 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.31 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.40 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.50 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – June 2019 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.