Sap Se Sap Basis vulnerabilities
2 known vulnerabilities affecting sap_se/sap_basis.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-0279HIGHCVSS 8.8fixed in from 7.00 to 7.02fixed in from 7.10 to 7.30+3 more2019-04-10
CVE-2019-0279 [HIGH] CWE-862 CVE-2019-0279: ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPI
ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary authorization checks in all circumstances for an authenticated user, resulting in escalation of privileges.
cvelistv5nvd
CVE-2018-2367HIGHCVSS 8.8vfrom 7.00 to 7.02vfrom 7.10 to 7.11+4 more2018-03-01
CVE-2018-2367 [HIGH] CWE-22 CVE-2018-2367: ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
cvelistv5nvd