CVE-2019-0337
published 2019-08-14CVE-2019-0337: Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and…
medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url thereby resulting in Reflected Cross-Site Scripting (XSS) vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_process_integration | — | — |
| sap | netweaver_process_integration | — | — |
| sap | netweaver_process_integration | — | — |
| sap | netweaver_process_integration | — | — |
| sap | netweaver_process_integration | — | — |
| sap | netweaver_process_integration | — | — |
| sap_se | sap_netweaver_process_integration | < 7.10 | 7.10 |
| sap_se | sap_netweaver_process_integration | < 7.11 | 7.11 |
| sap_se | sap_netweaver_process_integration | < 7.30 | 7.30 |
| sap_se | sap_netweaver_process_integration | < 7.31 | 7.31 |
| sap_se | sap_netweaver_process_integration | < 7.40 | 7.40 |
| sap_se | sap_netweaver_process_integration | < 7.50 | 7.50 |