CVE-2019-0277: SAP Hana Extended Application Services
Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
Affected products
- SAP Hana Extended Application Services: version 1.0 only
Published 2019-03-12. Last modified 2026-06-17.