4.3
CVSSv2

CVE-2019-0238

Published: 08/01/2019 Updated: 17/01/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

SAP Commerce (previously known as SAP Hybris Commerce), before version 6.7, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap hybris

Recent Articles

Make a SAP decision: Apply these security fixes if you're using German giant's software
The Register • Richard Chirgwin • 09 Jan 2019

11 patches ship on Patch Tuesday

While you were sighing your way through Microsoft's Patch Tuesday, enterprise vendor SAP slid 11 security advisories under your door. Top of the list is a depressingly familiar howler in SAP Cloud Connector pre-version 2.11.3: the software neglects authentication checks for functions that require user identity (CVE-2019-0246). A related bug in Cloud Connector (the same versions), CVE-2019-0247, can be exploited to achieve remote code injection. The German titan's systems management environment, ...