CVE Database
/

CVE-2019-0370

Back to search

CVE-2019-0370

Published: Oct 8, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.

VendorProductVersions

SAP SE

SAP Financial Consolidation

affected
< 10.0
affected
< 10.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now