CVE-2019-0319 describes a content injection vulnerability in SAP Gateway versions 7.5, 7.51, 7.52, and 7.53, allowing attackers to manipulate error messages displayed to users. This could lead to social engineering attacks where users are misled by spoofed information. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network without authentication, potentially impacting the integrity of information presented to users. Despite its severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, suggesting limited active exploitation. However, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.5CPE matchmatch criteria | cpe:2.3:a:sap:gateway:7.5:*:*:*:*:*:*:* | ||
7.51CPE matchmatch criteria | cpe:2.3:a:sap:gateway:7.51:*:*:*:*:*:*:* | ||
7.52CPE matchmatch criteria | cpe:2.3:a:sap:gateway:7.52:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:sap:gateway:7.53:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:sap:ui5:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.