CVE-2019-0271 is an XML External Entity (XEE) vulnerability affecting SAP ABAP Server (NetWeaver, Suite/ERP) and ABAP Platform, stemming from insufficient validation of untrusted XML documents. This medium-severity vulnerability (CVSS 6.5) can be exploited remotely with low complexity and no user interaction, potentially leading to high availability impact. While the vulnerability has been patched in various kernel versions, there is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:sap:advanced_business_application_programming_platform:-:*:*:*:*:*:*:* | ||
>= 7.00, <= 7.31CPE matchmatch criteria | cpe:2.3:a:sap:advanced_business_application_programming_server:*:*:*:*:*:*:*:* | ||
>= 7.40, <= 7.52CPE matchmatch criteria | cpe:2.3:a:sap:advanced_business_application_programming_server:*:*:*:*:*:*:*:* | ||
7.21CPE matchmatch criteria | cpe:2.3:a:sap:sap_kernel:7.21:*:*:*:*:*:*:* | ||
7.22CPE matchmatch criteria | cpe:2.3:a:sap:sap_kernel:7.22:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.