PT-2019-1732 · Sap · Sap Netweaver As For Abap/Abap Platform
Published
2019-02-12
·
Updated
2019-02-22
·
CVE-2019-0255
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS ABAP Platform versions 7.73 through 7.75
Description
The issue is related to insufficient input validation, which can be exploited by a remote attacker to elevate privileges. This behavior may lead to a situation where a business user gains access to the full SAP Menu, also known as the 'Easy Access Menu', potentially allowing any user to leverage privileges to business functionality.
Recommendations
For versions 7.73 through 7.75, consider restricting access to the ABAP Server system to minimize the risk of exploitation until a proper fix is applied.
As a temporary workaround, limit the access to the full SAP Menu to prevent potential misuse of business functionality.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As For Abap/Abap Platform