CVE-2019-0271
Estado: ModificadaMedia (6.5)—
ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.21 or 7.22, that is ABAP Server 7.00 to 7.31 and Kernel 7.45, 7.49 or 7.53, that is ABAP Server 7.40 to 7.52 or ABAP Platform. For more recent updates please refer to Security Note 2870067 (which supersedes the solution of Security Note 2736825) in the reference section below.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.44%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-20
Referencias
- http://www.securityfocus.com/bid/107355
- https://launchpad.support.sap.com/#/notes/2736825
- https://launchpad.support.sap.com/#/notes/2870067
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812
- http://www.securityfocus.com/bid/107355
- https://launchpad.support.sap.com/#/notes/2736825
- https://launchpad.support.sap.com/#/notes/2870067
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-0271",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP SE",
"product": "ABAP Server",
"versions": [
{
"status": "affected",
"version": "< from 7.00 to 7.31"
}
]
},
{
"vendor": "SAP SE",
"product": "ABAP Server & Platform",
"versions": [
{
"status": "affected",
"version": "< from 7.40 to 7.52"
}
]
}
]
}
],
"published": "2019-03-12T22:29:00.487",
"references": [
{
"url": "http://www.securityfocus.com/bid/107355",
"tags": [
"Broken Link"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2736825",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2870067",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "http://www.securityfocus.com/bid/107355",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2736825",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2870067",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.21 or 7.22, that is ABAP Server 7.00 to 7.31 and Kernel 7.45, 7.49 or 7.53, that is ABAP Server 7.40 to 7.52 or ABAP Platform. For more recent updates please refer to Security Note 2870067 (which supersedes the solution of Security Note 2736825) in the reference section below."
},
{
"lang": "es",
"value": "El servidor ABAP (utilizado en NetWeaver y Suite / ERP) y la plataforma ABAP no validan suficientemente un documento XML aceptado de una fuente no segura, lo que genera una vulnerabilidad de entidad externa XML (XEE). Se corrigió en Kernel 7.21 o 7.22, que es el Servidor ABAP 7.00 a 7.31 y Kernel 7.45, 7.49 o 7.53, que es el Servidor ABAP 7.40 a 7.52 o la Plataforma ABAP. Para actualizaciones más recientes, consulte la Nota de seguridad 2870067 (que reemplaza la solución de la Nota de seguridad 2736825) en la sección de referencia a continuación."
}
],
"lastModified": "2026-06-17T02:08:06.583",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:advanced_business_application_programming_platform:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9F4E561-9FA1-445C-822A-F46AA9AEA760"
},
{
"criteria": "cpe:2.3:a:sap:advanced_business_application_programming_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EEE02B80-95AF-4B35-B2CF-EE90B32DA3BA",
"versionEndIncluding": "7.31",
"versionStartIncluding": "7.00"
},
{
"criteria": "cpe:2.3:a:sap:advanced_business_application_programming_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "099C5E3A-0C59-437A-8353-441A5A059D16",
"versionEndIncluding": "7.52",
"versionStartIncluding": "7.40"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:sap_kernel:7.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1DB2B37-EC52-4FE6-9861-A98A9E365B61"
},
{
"criteria": "cpe:2.3:a:sap:sap_kernel:7.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80D1ECE8-0465-4B82-A0B7-BC55438FFC43"
},
{
"criteria": "cpe:2.3:a:sap:sap_kernel:7.45:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "517E04CB-B712-477E-8F64-B35F9D0D932B"
},
{
"criteria": "cpe:2.3:a:sap:sap_kernel:7.49:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "018F8061-43B6-4F29-B914-C779569C58CD"
},
{
"criteria": "cpe:2.3:a:sap:sap_kernel:7.53:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F7EA62C-67A6-4971-AC33-D5A3D390CE52"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}