CVE-2019-0316
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the victim is tricked to click on those malicious links, resulting in reflected Cross Site Scripting vulnerability.
SAP NetWeaver Process Integration, versiones: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 a 7.11, 7.30, 7.31, 7.40, 7.50, no valida suficientemente las entradas controladas por el usuario, lo que permite a un atacante que posee privilegios de administrador leer y modificar datos del navegador de la víctima , al inyectar scripts maliciosos en ciertos servlets, que se ejecutarán cuando se engañe a la víctima para que haga clic en esos enlaces maliciosos, lo que da como resultado una vulnerabilidad de Cross Site Scripting reflejada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-26 CVE Reserved
- 2019-06-14 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242 | 2020-02-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Netweaver Process Integration Search vendor "Sap" for product "Netweaver Process Integration" | 7.10 Search vendor "Sap" for product "Netweaver Process Integration" and version "7.10" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Process Integration Search vendor "Sap" for product "Netweaver Process Integration" | 7.11 Search vendor "Sap" for product "Netweaver Process Integration" and version "7.11" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Process Integration Search vendor "Sap" for product "Netweaver Process Integration" | 7.20 Search vendor "Sap" for product "Netweaver Process Integration" and version "7.20" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Process Integration Search vendor "Sap" for product "Netweaver Process Integration" | 7.30 Search vendor "Sap" for product "Netweaver Process Integration" and version "7.30" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Process Integration Search vendor "Sap" for product "Netweaver Process Integration" | 7.31 Search vendor "Sap" for product "Netweaver Process Integration" and version "7.31" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Process Integration Search vendor "Sap" for product "Netweaver Process Integration" | 7.40 Search vendor "Sap" for product "Netweaver Process Integration" and version "7.40" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Process Integration Search vendor "Sap" for product "Netweaver Process Integration" | 7.50 Search vendor "Sap" for product "Netweaver Process Integration" and version "7.50" | - |
Affected
|