Vulnerabilities > CVE-2019-0340 - XXE vulnerability in SAP Enable NOW 10

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
sap
CWE-611

Summary

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability. This issue affects the file upload at multiple locations. An attacker can read local XXE files.

Vulnerable Configurations

Part Description Count
Application
Sap
2