{"api_version":"1","generated_at":"2026-07-23T10:20:41+00:00","cve":"CVE-2019-0301","urls":{"html":"https://cve.report/CVE-2019-0301","api":"https://cve.report/api/cve/CVE-2019-0301.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-0301","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-0301"},"summary":{"title":"CVE-2019-0301","description":"Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing.","state":"PUBLIC","assigner":"cna@sap.com","published_at":"2019-05-14 21:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-269"],"metrics":[],"references":[{"url":"https://launchpad.support.sap.com/#/notes/2784307","name":"https://launchpad.support.sap.com/#/notes/2784307","refsource":"MISC","tags":["Permissions Required","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032","name":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032","refsource":"MISC","tags":["Vendor Advisory"],"title":"SAP Security Patch Day – May 2019 - Product Security Response at SAP - Community Wiki","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-0301","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-0301","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"301","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"identity_management","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"301","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"identity_management","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-0301","ASSIGNER":"cna@sap.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"SAP SE","product":{"product_data":[{"product_name":"SAP Identity Management (REST Interface)","version":{"version_data":[{"version_name":"<","version_value":"2"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Other"}]}]},"references":{"reference_data":[{"url":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032","refsource":"MISC","name":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032"},{"url":"https://launchpad.support.sap.com/#/notes/2784307","refsource":"MISC","name":"https://launchpad.support.sap.com/#/notes/2784307"}]}},"nvd":{"publishedDate":"2019-05-14 21:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-269"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:identity_management:2.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"301","Ordinal":"136709","Title":"CVE-2019-0301","CVE":"CVE-2019-0301","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"301","Ordinal":"1","NoteData":"Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"301","Ordinal":"2","NoteData":"2019-05-14","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"301","Ordinal":"3","NoteData":"2019-05-14","Type":"Other","Title":"Modified"}]}}}