// For flags

CVE-2019-0255

 

Severity Score

8.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly. That behavior may lead to situation, where business user achieves access to the full SAP Menu, that is 'Easy Access Menu'. The situation can be misused by any user to leverage privileges to business functionality.

SAP NetWeaver AS ABAP Platform, en Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fracasa a la hora de validar el tipo de instalación para un sistema ABAP Server correctamente. Este comportamiento podría conducir a una situación por la cual el usuario de negocio logra acceder al menú completo de SAP. Esto se conoce como "Easy Access Menu". Esta situación puede ser aprovechada por cualquier usuario para elevar privilegios a la funcionalidad de negocio.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-11-26 CVE Reserved
  • 2019-02-15 CVE Published
  • 2024-02-09 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Advanced Business Application Programming Platform Kernel
Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel"
7.73
Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" and version "7.73"
-
Affected
Sap
Search vendor "Sap"
Advanced Business Application Programming Platform Kernel
Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel"
7.74
Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" and version "7.74"
-
Affected
Sap
Search vendor "Sap"
Advanced Business Application Programming Platform Kernel
Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel"
7.75.
Search vendor "Sap" for product "Advanced Business Application Programming Platform Kernel" and version "7.75."
-
Affected
Sap
Search vendor "Sap"
Advanced Business Application Programming Platform Krnl64nuc
Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64nuc"
7.74
Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64nuc" and version "7.74"
-
Affected
Sap
Search vendor "Sap"
Advanced Business Application Programming Platform Krnl64uc
Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc"
7.73
Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc" and version "7.73"
-
Affected
Sap
Search vendor "Sap"
Advanced Business Application Programming Platform Krnl64uc
Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc"
7.74
Search vendor "Sap" for product "Advanced Business Application Programming Platform Krnl64uc" and version "7.74"
-
Affected