SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0340

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability.

MEDIUM 5.4EPSS 0.69%

Does this matter?

Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.

Description

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability. This issue affects the file upload at multiple locations. An attacker can read local XXE files.

CVSS 3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS
0.69% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
sap/enable now
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.