CVE-2019-0298: SAP E-Commerce
Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.
SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Fixed in the following components SAP-CRMJAV SAP-CRMWEB SAP-SHRWEB SAP-SHRJAV SAP-CRMAPP SAP-SHRAPP, versions 7.30, 7.31, 7.32, 7.33, 7.54.
Affected products
- SAP E-Commerce: version 7.30 only; version 7.31 only; version 7.32 only; version 7.33 only; version 7.54 only
Published 2019-05-14. Last modified 2026-06-17.