CVE-2019-0319
Estado: ModificadaAlta (7.5)—
The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service when it's not.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.51%
- Percentil entre todas las CVEs puntuadas: 84
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-74, CWE-79
Referencias
- http://packetstormsecurity.com/files/153661/SAPUI5-1.0.0-SAP-Gateway-7.5-7.51-7.52-7.53-Content-Spoofing.html
- http://www.securityfocus.com/bid/109074
- https://cxsecurity.com/ascii/WLB-2019050283
- https://drive.google.com/open?id=1aGFqggvydehSK7MFIsfKW7tO60yiF55f
- https://launchpad.support.sap.com/#/notes/2752614
- https://launchpad.support.sap.com/#/notes/2911267
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575
- http://packetstormsecurity.com/files/153661/SAPUI5-1.0.0-SAP-Gateway-7.5-7.51-7.52-7.53-Content-Spoofing.html
- http://www.securityfocus.com/bid/109074
- https://cxsecurity.com/ascii/WLB-2019050283
- https://drive.google.com/open?id=1aGFqggvydehSK7MFIsfKW7tO60yiF55f
- https://launchpad.support.sap.com/#/notes/2752614
- https://launchpad.support.sap.com/#/notes/2911267
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-0319",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP SE",
"product": "SAP Gateway",
"versions": [
{
"status": "affected",
"version": "< 7.5"
},
{
"status": "affected",
"version": "< 7.51"
},
{
"status": "affected",
"version": "< 7.52"
},
{
"status": "affected",
"version": "< 7.53"
}
]
}
]
}
],
"published": "2019-07-10T19:15:10.220",
"references": [
{
"url": "http://packetstormsecurity.com/files/153661/SAPUI5-1.0.0-SAP-Gateway-7.5-7.51-7.52-7.53-Content-Spoofing.html",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cna@sap.com"
},
{
"url": "http://www.securityfocus.com/bid/109074",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cna@sap.com"
},
{
"url": "https://cxsecurity.com/ascii/WLB-2019050283",
"tags": [
"Third Party Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://drive.google.com/open?id=1aGFqggvydehSK7MFIsfKW7tO60yiF55f",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2752614",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2911267",
"source": "cna@sap.com"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "http://packetstormsecurity.com/files/153661/SAPUI5-1.0.0-SAP-Gateway-7.5-7.51-7.52-7.53-Content-Spoofing.html",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/109074",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cxsecurity.com/ascii/WLB-2019050283",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://drive.google.com/open?id=1aGFqggvydehSK7MFIsfKW7tO60yiF55f",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2752614",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2911267",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523994575",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service when it's not."
},
{
"lang": "es",
"value": "SAP Gateway, versiones 7.5, 7.51, 7.52 y 7.53, permite a un atacante inyectar contenido que es desplegado en forma de mensaje de error. Por lo tanto, un atacante podría engañar a un usuario para que crea que esta información es de servicio legítimo cuando no lo es."
}
],
"lastModified": "2026-06-17T02:08:10.310",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:gateway:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55156CCE-56A8-43FD-87C3-1A4849656FBD"
},
{
"criteria": "cpe:2.3:a:sap:gateway:7.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1165027E-EAC9-4163-B2BC-0FD2E76D1665"
},
{
"criteria": "cpe:2.3:a:sap:gateway:7.52:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "014A32BF-E695-4382-AE81-0209846FA99D"
},
{
"criteria": "cpe:2.3:a:sap:gateway:7.53:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E8220FC-05F3-4BE7-AF38-3BD917C5631A"
},
{
"criteria": "cpe:2.3:a:sap:ui5:1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A38FF70-E888-4768-82A8-3A44620F1F6A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}