PT-2019-4583 · Sap · Sap Gateway

Rafael Fontes Souza

·

Published

2019-07-09

·

Updated

2020-08-24

·

CVE-2019-0319

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions SAP Gateway versions 7.5 through 7.53
Description The issue allows an attacker to inject content that is displayed as an error message, potentially misleading users into believing the information comes from a legitimate service. This is due to the lack of measures to neutralize special elements, which could allow a remote attacker to impact data integrity.
Recommendations For SAP Gateway versions 7.5 through 7.53, consider implementing measures to neutralize special elements and validate user input to prevent content injection. As a temporary workaround, restrict access to error messages that could be manipulated by an attacker.

Exploit

Fix

Special Elements Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00643
CVE-2019-0319

Affected Products

Sap Gateway