CVE-2019-0361
CVE-2019-0361
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Sep 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected products
SAP SE · SAP Supplier Relationship Management (Master Data Management Catalog) (SRM_MDM_CAT)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →