CVE-2019-0279

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/04/2019
Last modified:
24/08/2020

Description

ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary authorization checks in all circumstances for an authenticated user, resulting in escalation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:* 7.00 (including) 7.02 (including)
cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:* 7.10 (including) 7.30 (including)
cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:* 7.50 (including) 7.53 (including)
cpe:2.3:a:sap:business_application_software_integrated_solution:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_application_software_integrated_solution:7.40:*:*:*:*:*:*:*