Vulnerability CVE-2019-0293


Published: 2019-05-14

Description:
Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
SAP -> Sap solution manager system 

 References:
http://www.securityfocus.com/bid/108324
https://launchpad.support.sap.com/#/notes/2756625
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032

Copyright 2024, cxsecurity.com

 

Back to Top