PT-2019-1732 · Sap · Sap Netweaver As For Abap/Abap Platform
Publicado
2019-02-12
·
Atualizado
2019-02-22
·
CVE-2019-0255
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS ABAP Platform versions 7.73 through 7.75
Description
The issue is related to insufficient input validation, which can be exploited by a remote attacker to elevate privileges. This behavior may lead to a situation where a business user gains access to the full SAP Menu, also known as the 'Easy Access Menu', potentially allowing any user to leverage privileges to business functionality.
Recommendations
For versions 7.73 through 7.75, consider restricting access to the ABAP Server system to minimize the risk of exploitation until a proper fix is applied.
As a temporary workaround, limit the access to the full SAP Menu to prevent potential misuse of business functionality.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Netweaver As For Abap/Abap Platform