CVE-2019-0293
Summary
| CVE | CVE-2019-0293 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-14 21:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740). |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Sap Solution Manager System | 2008_1_700 | All | All | All |
| Application | Sap | Sap Solution Manager System | 2008_1_710 | All | All | All |
| Application | Sap | Sap Solution Manager System | 2008_1_740 | All | All | All |
| Application | Sap | Sap Solution Manager System | 2008_1_700 | All | All | All |
| Application | Sap | Sap Solution Manager System | 2008_1_710 | All | All | All |
| Application | Sap | Sap Solution Manager System | 2008_1_740 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – May 2019 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| SAP Solution Manager CVE-2019-0293 Remote Authorization Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.