Medium severity6.1NVD Advisory· Published May 14, 2019· Updated Jun 17, 2026
CVE-2019-0298
CVE-2019-0298
Description
SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Fixed in the following components SAP-CRMJAV SAP-CRMWEB SAP-SHRWEB SAP-SHRJAV SAP-CRMAPP SAP-SHRAPP, versions 7.30, 7.31, 7.32, 7.33, 7.54.
Affected products
7cpe:2.3:a:sap:e-commerce:7.30:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:sap:e-commerce:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:e-commerce:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:e-commerce:7.32:*:*:*:*:*:*:*
- cpe:2.3:a:sap:e-commerce:7.33:*:*:*:*:*:*:*
- cpe:2.3:a:sap:e-commerce:7.54:*:*:*:*:*:*:*
- Range: 7.30, 7.31, 7.32, 7.33, 7.54
- SAP SE/SAP E-Commerce (SAP-CRMJAV, SAP-CRMWEB, SAP-SHRWEB, SAP-SHRJAV, SAP-CRMAPP, SAP-SHRAPP)v5Range: < 7.3
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/108314nvdThird Party AdvisoryVDB Entry
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.