CVE-2019-0257Missing Authorization in SE Abap Platform

Severity
8.8HIGHNVD
EPSS
0.6%
top 31.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 13

Description

Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5sap_se/abap_platform< from 7.0 to 7.02+6
NVDsap/netweaver_as_abap7.107.11+1
NVDsap/netweaver_application7.07.02+4

🔴Vulnerability Details

2
GHSA
GHSA-xg34-8qvc-j4hh: Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 72022-05-13
CVEList
CVE-2019-0257: Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 72019-02-15
CVE-2019-0257 — Missing Authorization | cvebase