VYPR
Medium severity6.5NVD Advisory· Published Nov 13, 2019· Updated Jun 17, 2026

CVE-2019-0385

CVE-2019-0385

Description

SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected products

3
  • SAP/Enable Nowllm-fuzzy2 versions
    <1908+ 1 more
    • (no CPE)range: <1908
    • cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:*range: <1908
  • SAP SE/SAP Enable Nowv5
    Range: < 1908

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.