CVE-2019-0255
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly. That behavior may lead to situation, where business user achieves access to the full SAP Menu, that is 'Easy Access Menu'. The situation can be misused by any user to leverage privileges to business functionality.
SAP NetWeaver AS ABAP Platform, en Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fracasa a la hora de validar el tipo de instalación para un sistema ABAP Server correctamente. Este comportamiento podría conducir a una situación por la cual el usuario de negocio logra acceder al menú completo de SAP. Esto se conoce como "Easy Access Menu". Esta situación puede ser aprovechada por cualquier usuario para elevar privilegios a la funcionalidad de negocio.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-26 CVE Reserved
- 2019-02-15 CVE Published
- 2024-02-09 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106987 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943 | 2019-02-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Advanced Business Application Programming Platform Kernel Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" | 7.73 Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" and version "7.73" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Advanced Business Application Programming Platform Kernel Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" | 7.74 Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" and version "7.74" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Advanced Business Application Programming Platform Kernel Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" | 7.75. Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" and version "7.75." | - |
Affected
| ||||||
Sap Search vendor "Sap" | Advanced Business Application Programming Platform Krnl64nuc Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64nuc" | 7.74 Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64nuc" and version "7.74" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Advanced Business Application Programming Platform Krnl64uc Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc" | 7.73 Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc" and version "7.73" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Advanced Business Application Programming Platform Krnl64uc Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc" | 7.74 Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc" and version "7.74" | - |
Affected
|