PT-2019-4462 · Sap · S4Core+3

Published

2019-11-12

·

Updated

2020-08-24

·

CVE-2019-0386

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP ERP Sales versions 6.0 through 6.06, 6.16 through 6.18 S4HANA Sales versions 1.0 through 1.04
Description The issue is related to insufficient authorization checks in the order processing functionality, which can lead to an escalation of privileges for an authenticated user. This can potentially allow a remote attacker to elevate their privileges.
Recommendations For SAP ERP Sales versions 6.0 through 6.06, 6.16 through 6.18, update to a version that includes the corrections, such as SAP APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18. For S4HANA Sales versions 1.0 through 1.04, update to a version that includes the corrections, such as S4CORE 1.0, 1.01, 1.02, 1.03, 1.04.

Fix

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00249
CVE-2019-0386

Affected Products

S4Core
S4Hana Sales
Sap Erp Sales
Sap Appl