SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the victim is tricked to click on those malicious links, resulting in reflected Cross Site Scripting vulnerability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: sap

Published: 2019-06-14T18:50:55

Updated: 2019-06-14T18:50:55

Reserved: 2018-11-26T00:00:00


Link: CVE-2019-0316

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-06-14T19:29:00.340

Modified: 2020-02-10T21:48:48.353


Link: CVE-2019-0316

JSON object: View

cve-icon Redhat Information

No data.

CWE