CVE-2019-0389

An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_java:7.1:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.2:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.3:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.4:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.5:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:*

History

21 Nov 2024, 04:16

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2814357 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/2814357 - Permissions Required, Vendor Advisory
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390 - Vendor Advisory

Information

Published : 2019-11-13 22:15

Updated : 2024-11-21 04:16


NVD link : CVE-2019-0389

Mitre link : CVE-2019-0389

CVE.ORG link : CVE-2019-0389


JSON object : View

Products Affected

sap

  • netweaver_application_server_java