HIGH
SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges
Published May 14, 2019
8.8
HIGHCVSS 3.0
EPSS 1.12%
Description
SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.
Affected products
-
- Version < 1.01StatusaffectedConstraints-
- Version < 1.02StatusaffectedConstraints-
- Version < 1.03StatusaffectedConstraints-
- Version
-
- Version < 6.0StatusaffectedConstraints-
- Version < 6.03StatusaffectedConstraints-
- Version < 6.04StatusaffectedConstraints-
- Version < 6.05StatusaffectedConstraints-
- Version < 6.06StatusaffectedConstraints-
- Version < 6.16StatusaffectedConstraints-
- Version < 6.17StatusaffectedConstraints-
- Version < 6.18StatusaffectedConstraints-
- Version < 8.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SAP SE | SAP Enterprise Financial Services (S4CORE) | n/a |
| ||||||||||||||||||||||||||||||
| SAP SE | SAP Treasury and Risk Management(EA-FINSERV) | n/a |
|
OR
- 6.0
- 6.03
- 6.04
- 6.05
- 6.06
- 6.16
- 6.17
- 6.18
- 8.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1053 Advisory
- https://launchpad.support.sap.com/#/notes/2744937 x_refsource_MISCPermissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1053 | Advisory | |
| https://launchpad.support.sap.com/#/notes/2744937 | x_refsource_MISCPermissions Required | |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published May 14, 2019
Updated Aug 4, 2024
Reserved Nov 26, 2018
Link CVE-2019-0280
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-1053 Assigner sap
Published May 14, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-1053