CVE-2019-0370
https://notcve.org/view.php?id=CVE-2019-0370
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection. Debido a la falta de comprobación de entrada, SAP Financial Consolidation, versiones anteriores a 10.0 y 10.1, permite a un atacante usar entradas diseñadas para interferir con la estructura de la consulta surrounding conllevando a la inyección de XPath. • https://launchpad.support.sap.com/#/notes/2806403 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050 • CWE-91: XML Injection (aka Blind XPath Injection) •
CVE-2019-0369
https://notcve.org/view.php?id=CVE-2019-0369
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability. SAP Financial Consolidation, versiones anteriores a 10.0 y 10.1, no codifica suficientemente las entradas controladas por el usuario, lo que permite a un atacante ejecutar scripts al cargar archivos que contienen scripts maliciosos, conllevando a una vulnerabilidad de tipo cross site scripting. • https://launchpad.support.sap.com/#/notes/2806403 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-2444
https://notcve.org/view.php?id=CVE-2018-2444
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. SAP BusinessObjects Financial Consolidation 10.0 y 10.1 no cifra lo suficiente las entradas controladas por el usuario, lo que resulta en una vulnerabilidad de Cross-Site Scripting (XSS). • http://www.securityfocus.com/bid/105087 https://launchpad.support.sap.com/#/notes/2621395 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •