Unrated severityNVD Advisory· Published Oct 8, 2019· Updated Aug 4, 2024
CVE-2019-0369
CVE-2019-0369
Description
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability.
Affected products
2- Range: <10.0
- SAP SE/SAP Financial Consolidationv5Range: < 10.0
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.commitrex_refsource_MISC
- wiki.scn.sap.com/wiki/pages/viewpage.actionmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.