VulnerabilityModified
CVE-2019-0293
Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700,…
MEDIUM 6.5EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- sap/sap solution manager system
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/108324Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2756625Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032Vendor Advisory
- http://www.securityfocus.com/bid/108324Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2756625Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.