CVE-2019-0370
Summary
| CVE | CVE-2019-0370 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-08 20:15:00 UTC |
| Updated | 2019-10-11 13:27:00 UTC |
| Description | Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection. |
Risk And Classification
Problem Types: CWE-91
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Financial Consolidation | 10.0 | All | All | All |
| Application | Sap | Financial Consolidation | 10.1 | All | All | All |
| Application | Sap | Financial Consolidation | 10.0 | All | All | All |
| Application | Sap | Financial Consolidation | 10.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required |
| SAP Security Patch Day – October 2019 - Product Security Response at SAP - SCN Wiki | CONFIRM | wiki.scn.sap.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.