First published: Tue Mar 12 2019(Updated: )
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.74, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, 7.74, 8.04, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, 7.74, 7.75, 8.04.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Advanced Business Application Programming Platform Kernel | =7.15 | |
SAP Advanced Business Application Programming Platform Kernel | =7.21 | |
SAP Advanced Business Application Programming Platform Kernel | =7.22 | |
SAP Advanced Business Application Programming Platform Kernel | =7.49 | |
SAP Advanced Business Application Programming Platform Kernel | =7.53 | |
SAP Advanced Business Application Programming Platform Kernel | =7.73 | |
SAP Advanced Business Application Programming Platform Kernel | =7.74 | |
SAP Advanced Business Application Programming Platform Kernel | =7.75 | |
SAP Advanced Business Application Programming Platform Kernel | =8.04 | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.21 | |
SAP Advanced Business Application Programming Platform | =7.21ext | |
SAP Advanced Business Application Programming Platform | =7.22 | |
SAP Advanced Business Application Programming Platform | =7.22ext | |
SAP Advanced Business Application Programming Platform | =7.49 | |
SAP Advanced Business Application Programming Platform | =7.73 | |
SAP Advanced Business Application Programming Platform | =7.74 | |
SAP Advanced Business Application Programming Platform | =8.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0270 is high with a severity value of 8.8.
The affected software for CVE-2019-0270 is SAP Advanced Business Application Programming Platform Kernel versions 7.15, 7.21, and 7.22.
CVE-2019-0270 has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT.
You can find more information about CVE-2019-0270 at the following references: SecurityFocus BID 107377, SAP Note 2727689, and SAP Community Network wiki page.
The CWE ID for CVE-2019-0270 is CWE-862.