CVE-2019-0308
An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed…
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
- EPSS
- 0.86% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sap/e-commerce
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2773493Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2773493Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.