VulnerabilityModified
CVE-2019-0277
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
MEDIUM 6.5EPSS 2.13%
Does this matter?
Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.
Description
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 2.13% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- sap/hana extended application services
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/107356Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2764283Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080Vendor Advisory
- http://www.securityfocus.com/bid/107356Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2764283Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.