CVE-2019-0254Cross-site Scripting in SE SAP Disclosure Management

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 46.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 14

Description

SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5sap_se/sap_disclosure_management< 10.1 Stack 1301

🔴Vulnerability Details

2
GHSA
GHSA-7cwc-82pf-56c6: SAP Disclosure Management (before version 102022-05-14
CVEList
CVE-2019-0254: SAP Disclosure Management (before version 102019-02-15
CVE-2019-0254 — Cross-site Scripting | cvebase