CVE-2019-0311

Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-controlled inputs, this makes it possible for an attacker to send unwanted scripts to the browser of the victim using unwanted input and execute malicious code there, resulting in Cross-Site Scripting (XSS) vulnerability.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:r\/3_enterprise:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:602:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:606:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:616:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:617:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-06-12 17:29

Updated : 2024-02-28 17:08


NVD link : CVE-2019-0311

Mitre link : CVE-2019-0311

CVE.ORG link : CVE-2019-0311


JSON object : View

Products Affected

sap

  • r\/3_enterprise
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')