Vulnerability Description
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Financial Consolidation | 10.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2806403Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2806403Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050Vendor Advisory
FAQ
What is CVE-2019-0370?
CVE-2019-0370 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading t...
How severe is CVE-2019-0370?
CVE-2019-0370 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0370?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Financial Consolidation.