Medium severity5.4NVD Advisory· Published Oct 8, 2019· Updated Jun 17, 2026
CVE-2019-0369
CVE-2019-0369
Description
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability.
Affected products
4<10.0, <10.1+ 2 more
- (no CPE)range: <10.0, <10.1
- cpe:2.3:a:sap:financial_consolidation:10.0:*:*:*:*:*:*:*
- cpe:2.3:a:sap:financial_consolidation:10.1:*:*:*:*:*:*:*
- SAP SE/SAP Financial Consolidationv5Range: < 10.0
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.