PT-2019-1770 · Sap · Sap Disclosure Management

Published

2019-02-12

·

Updated

2019-02-20

·

CVE-2019-0254

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Disclosure Management versions prior to 10.1 Stack 1301
Description The issue is related to insufficient encoding of user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability is associated with a lack of protection for the web page structure, which could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 10.1 Stack 1301, update to version 10.1 Stack 1301 or later to resolve the issue. As a temporary workaround, consider restricting access to the SAP Disclosure Management application until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01414
CVE-2019-0254

Affected Products

Sap Disclosure Management