PT-2019-4567 · Sap · Sap Netweaver As For Abap/Abap Platform

CVE-2019-0257

·

Publicado

2019-02-15

·

Atualizado

2022-10-05

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS ABAP Platform versions prior to 7.02 SAP NetWeaver AS ABAP Platform versions prior to 7.11 SAP NetWeaver AS ABAP Platform versions 7.30 SAP NetWeaver AS ABAP Platform versions 7.31 SAP NetWeaver AS ABAP Platform versions 7.40 SAP NetWeaver AS ABAP Platform versions prior to 7.53 SAP NetWeaver AS ABAP Platform versions prior to 7.75
Description The issue is related to the customization functionality of the platform, which does not perform necessary authorization checks for an authenticated user. This results in an escalation of privileges. The vulnerability can be exploited by a remote attacker to elevate their privileges.
Recommendations For versions 7.30, 7.31, and 7.40, update to a version with the necessary security fixes. For versions prior to 7.02, update to version 7.02 or later. For versions prior to 7.11, update to version 7.11 or later. For versions prior to 7.53, update to version 7.53 or later. For versions prior to 7.75, update to version 7.75 or later.

Correção

Improper Authorization

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00627
CVE-2019-0257

Produtos afetados

Sap Netweaver As For Abap/Abap Platform