CVE-2019-0311

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
12/06/2019
Last modified:
14/06/2019

Description

Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-controlled inputs, this makes it possible for an attacker to send unwanted scripts to the browser of the victim using unwanted input and execute malicious code there, resulting in Cross-Site Scripting (XSS) vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:r\/3_enterprise:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:602:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:606:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:616:*:*:*:*:*:*:*
cpe:2.3:a:sap:r\/3_enterprise:617:*:*:*:*:*:*:*