CVE-2019-0270
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.74, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, 7.74, 8.04, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, 7.74, 7.75, 8.04.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- sap/advanced business application programming platform kernel · sap/advanced business application programming platform krnl32nuc · sap/advanced business application programming platform krnl32uc · sap/advanced business application programming platform krnl64nuc · sap/advanced business application programming platform krnl64uc
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/107377Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2727689Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080Vendor Advisory
- http://www.securityfocus.com/bid/107377Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2727689Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.