CVE-2018-2419: Medium severity sap sapscore vulnerability
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2419?
The severity of CVE-2018-2419 is medium with a severity value of 4.6.
What is the affected software for CVE-2018-2419?
The affected software for CVE-2018-2419 includes SAPSCORE 1.11, SAPSCORE 1.12, S4CORE 1.01, S4CORE 1.02, EA-FINSERV 6.04, EA-FINSERV 6.05, EA-FINSERV 6.06, EA-FINSERV 6.16, EA-FINSERV 6.17, EA-FINSERV 6.18, and EA-FINSERV 8.0.
What is the vulnerability description of CVE-2018-2419?
CVE-2018-2419 is a vulnerability in SAP Enterprise Financial Services that allows an authenticated user to escalate privileges due to the lack of necessary authorization checks.
Are there any references available for CVE-2018-2419?
Yes, references for CVE-2018-2419 include http://www.securityfocus.com/bid/104116, https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/, and https://launchpad.support.sap.com/#/notes/2596627.
What is the CWE category for CVE-2018-2419?
CVE-2018-2419 belongs to CWE category 862.