First published: Tue Jan 08 2019(Updated: )
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Cloud Connector | <2.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0246 is classified as a high-severity vulnerability due to the lack of authentication checks.
To fix CVE-2019-0246, upgrade to SAP Cloud Connector version 2.11.3 or later.
CVE-2019-0246 allows unauthorized access to functionalities that require user identity, which can lead to data breaches.
Versions of SAP Cloud Connector prior to 2.11.3 are affected by CVE-2019-0246.
Yes, CVE-2019-0246 is exploitable remotely, making it crucial to apply the necessary updates.