CVE-2019-0257
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Affected (7)
Products: Sap: Netweaver Application Server Abap, Netweaver As Abap
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.0 to 7.02 | |
| From 7.10 to 7.11 |
References (6)
Source: cna@sap.com
Permissions RequiredVendor Advisory
Source: cna@sap.com
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Timeline
No history available yet.