CVE Database · CVE-2019-0340
CVSS v3.1
N/A
EPSS
0.69%
Published
Aug 14, 2019
Modified
Nov 21, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability. This issue affects the file upload at multiple locations. An attacker can read local XXE files.
Weaknesses (CWE)
Affected Products (1)
References (4)