Vulnerability CVE-2019-0370


Published: 2019-10-08

Description:
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.

Type:

CWE-91

(XML Injection (aka Blind XPath Injection))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
SAP -> Financial consolidation 

 References:
https://launchpad.support.sap.com/#/notes/2806403
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050

Copyright 2024, cxsecurity.com

 

Back to Top