← Back

CVE-2019-0386

nvd nist
Published: Nov 13, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: NVD

Description

Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges.

Affected (14)

2 products
Erp Sales
S4hana Sales
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 6.02
Version 6.03
Version 6.04
Version 6.05
Version 6.06
Version 6.0
Version 6.16
Version 6.17
Version 6.18
Sap
Version 1.01
Version 1.02
Version 1.03
Version 1.04
Version 1.0

References (4)

Source: cna@sap.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.