SAP Gateway CVE-2019-0319 Content Injection Vulnerability
BID:109074
CVE-2019-319 |Info
SAP Gateway CVE-2019-0319 Content Injection Vulnerability
| Bugtraq ID: | 109074 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-0319 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2019 12:00AM |
| Updated: | Jul 09 2019 12:00AM |
| Credit: | SAP |
| Vulnerable: |
SAP Netweaver Gateway 7.53 SAP Netweaver Gateway 7.52 SAP Netweaver Gateway 7.51 SAP Netweaver Gateway 7.5 |
| Not Vulnerable: | |
Discussion
SAP Gateway CVE-2019-0319 Content Injection Vulnerability
SAP Gateway is prone to a content injection vulnerability because the application fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied content to be passed in context of the affected application ; Other attacks are also possible.
SAP Gateway versions 7.5, 7.51, 7.52 and 7.53 are vulnerable.
SAP Gateway is prone to a content injection vulnerability because the application fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied content to be passed in context of the affected application ; Other attacks are also possible.
SAP Gateway versions 7.5, 7.51, 7.52 and 7.53 are vulnerable.
Exploit / POC
SAP Gateway CVE-2019-0319 Content Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: https://[removed]/[email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: https://[removed]/[email protected].
Solution / Fix
SAP Gateway CVE-2019-0319 Content Injection Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
SAP Gateway CVE-2019-0319 Content Injection Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Patch Day �?? July 2019 (SAP)
- Security Note #2752614 (SAP)