cbcvebase.
CVE-2019-0271
published 2019-03-12

CVE-2019-0271: ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an…

PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.44%
70.0th percentile
ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.21 or 7.22, that is ABAP Server 7.00 to 7.31 and Kernel 7.45, 7.49 or 7.53, that is ABAP Server 7.40 to 7.52 or ABAP Platform. For more recent updates please refer to Security Note 2870067 (which supersedes the solution of Security Note 2736825) in the reference section below.

Affected

9 ranges
VendorProductVersion rangeFixed in
sapadvanced_business_application_programming_server7.00 – 7.31
sapadvanced_business_application_programming_server7.40 – 7.52
sapsap_kernel
sapsap_kernel
sapsap_kernel
sapsap_kernel
sapsap_kernel
sap_seabap_server< from 7.00 to 7.31from 7.00 to 7.31
sap_seabap_server_platform< from 7.40 to 7.52from 7.40 to 7.52

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.