CVE-2019-0254
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected products
SAP SE · SAP Disclosure Management