Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0271


ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.21 or 7.22, that is ABAP Server 7.00 to 7.31 and Kernel 7.45, 7.49 or 7.53, that is ABAP Server 7.40 to 7.52 or ABAP Platform. For more recent updates please refer to Security Note 2870067 (which supersedes the solution of Security Note 2736825) in the reference section below.


Published

2019-03-12T22:29:00.487

Last Modified

2024-11-21T04:16:36.860

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap advanced_business_application_programming_platform - Yes
Application sap advanced_business_application_programming_server ≤ 7.31 Yes
Application sap advanced_business_application_programming_server ≤ 7.52 Yes
Application sap sap_kernel 7.21 Yes
Application sap sap_kernel 7.22 Yes
Application sap sap_kernel 7.45 Yes
Application sap sap_kernel 7.49 Yes
Application sap sap_kernel 7.53 Yes

References