Vulnerabilities > CVE-2019-0277 - XXE vulnerability in SAP Hana Extended Application Services 1.0

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
sap
CWE-611

Summary

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).

Vulnerable Configurations

Part Description Count
Application
Sap
1