ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.74, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, 7.74, 8.04, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, 7.74, 7.75, 8.04.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/107377 | Third Party Advisory |
https://launchpad.support.sap.com/#/notes/2727689 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080 | Vendor Advisory |
http://www.securityfocus.com/bid/107377 | Third Party Advisory |
https://launchpad.support.sap.com/#/notes/2727689 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/107377 - Third Party Advisory | |
References | () https://launchpad.support.sap.com/#/notes/2727689 - Permissions Required, Vendor Advisory | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080 - Vendor Advisory |
Information
Published : 2019-03-12 22:29
Updated : 2024-11-21 04:16
NVD link : CVE-2019-0270
Mitre link : CVE-2019-0270
CVE.ORG link : CVE-2019-0270
JSON object : View
Products Affected
sap
- advanced_business_application_programming_platform_krnl32nuc
- advanced_business_application_programming_platform_krnl32uc
- advanced_business_application_programming_platform_krnl64uc
- advanced_business_application_programming_platform_kernel
- advanced_business_application_programming_platform_krnl64nuc
CWE
CWE-862
Missing Authorization