CVE-2019-0349

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/08/2019
Last modified:
24/08/2020

Description

SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute “Go to statement” without possessing the authorization S_DEVELOP DEBUG 02, resulting in Missing Authorization Check

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.21:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.21ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.22:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.22ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.53:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.73:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.75:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.76:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.77:*:*:*:*:*:*:*