CVE-2019-0255Improper Input Validation in SAP Advanced Business Application Programming Platform Kernel

Severity
8.1HIGHNVD
EPSS
0.3%
top 43.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 14

Description

SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly. That behavior may lead to situation, where business user achieves access to the full SAP Menu, that is 'Easy Access Menu'. The situation can be misused by any user to leverage privileges to business functionality.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

🔴Vulnerability Details

2
GHSA
GHSA-mxh7-rq99-375w: SAP NetWeaver AS ABAP Platform, Krnl64nuc 72022-05-14
CVEList
CVE-2019-0255: SAP NetWeaver AS ABAP Platform, Krnl64nuc 72019-02-15
CVE-2019-0255 — Improper Input Validation in SAP | cvebase