First published: Tue Jan 08 2019(Updated: )
Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Bw\/4hana | =1.0-sp08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0243 is considered to be a high-severity vulnerability due to the potential for privilege escalation.
To resolve CVE-2019-0243, update to SAP BW/4HANA version 1.0 SP08 or later.
CVE-2019-0243 affects the masterdata maintenance functionality in SAP BW/4HANA.
Authenticated users of SAP BW/4HANA may be impacted by CVE-2019-0243 if they exploit the lack of necessary authorization checks.
CVE-2019-0243 may allow an attacker to escalate privileges and gain unauthorized access to sensitive data.