Medium severity6.5NVD Advisory· Published Mar 12, 2019· Updated Jun 17, 2026
CVE-2019-0277
CVE-2019-0277
Description
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
Affected products
3cpe:2.3:a:sap:hana_extended_application_services:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:hana_extended_application_services:1.0:*:*:*:*:*:*:*
- (no CPE)range: 1
- SAP SE/SAP HANA Extended Application Servicesv5Range: < 1
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/107356nvdThird Party AdvisoryVDB Entry
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.