Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0370


Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.


Published

2019-10-08T20:15:11.090

Last Modified

2024-11-21T04:16:45.313

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-91

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap financial_consolidation 10.0 Yes
Application sap financial_consolidation 10.1 Yes

References