ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.21 or 7.22, that is ABAP Server 7.00 to 7.31 and Kernel 7.45, 7.49 or 7.53, that is ABAP Server 7.40 to 7.52 or ABAP Platform. For more recent updates please refer to Security Note 2870067 (which supersedes the solution of Security Note 2736825) in the reference section below.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2019-03-12T22:00:00
Updated: 2024-08-04T17:44:16.313Z
Reserved: 2018-11-26T00:00:00
Link: CVE-2019-0271
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-12T22:29:00.487
Modified: 2024-11-21T04:16:36.860
Link: CVE-2019-0271
Redhat
No data.