ZeroHour

CVE-2019-0340

CVSS 3.0
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability. This issue affects the file upload at multiple locations. An attacker can read local XXE files.

Vendors
sap
Products
enable now
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.