CVE-2019-0369
published 2019-10-08CVE-2019-0369: SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by…
medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | financial_consolidation | — | — |
| sap | financial_consolidation | — | — |
| sap_se | sap_financial_consolidation | < 10.0 | 10.0 |
| sap_se | sap_financial_consolidation | < 10.1 | 10.1 |