CVE-2019-0340

MEDIUM

SAP Enable Now < 1902 - XML External Entity Injection via File Upload

Title source: llm
STIX 2.1

Description

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability. This issue affects the file upload at multiple locations. An attacker can read local XXE files.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2794742

Scores

CVSS v3 5.4
EPSS 0.0013
EPSS Percentile 31.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-611
Status published
Products (1)
sap/enable_now < 1902
Published Aug 14, 2019
Tracked Since Feb 18, 2026