First published: Tue Jan 08 2019(Updated: )
Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =7.5 | |
SAP NetWeaver | =7.51 | |
SAP NetWeaver | =7.52 | |
SAP NetWeaver | =7.53 | |
SAP Basis | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0248 is medium with a CVSS score of 5.9.
SAP NetWeaver versions 7.5, 7.51, 7.52, 7.53 and SAP Basis version 7.5 are affected by CVE-2019-0248.
An attacker can exploit CVE-2019-0248 to access information that would otherwise be restricted.
CVE-2019-0248 has been fixed in SAP_GWFND versions 7.5, 7.51, 7.52, and 7.53, as well as SAP_BASIS version 7.5.
You can find more information about CVE-2019-0248 in the following references: [1] http://www.securityfocus.com/bid/106471, [2] https://launchpad.support.sap.com/#/notes/2723142, [3] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=509151985