First published: Tue Mar 12 2019(Updated: )
Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorization check for an authenticated user, potentially resulting in escalation of privileges.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Banking Services From Sap | =9.0 | |
Sap S\/4hana Financial Products Subledger | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2019-0276 vulnerability has a medium severity rating due to inadequate authorization checks.
To fix CVE-2019-0276, apply the relevant security patches provided by SAP for the affected software versions.
CVE-2019-0276 affects SAP Banking Services from SAP version 9.0 and SAP S/4HANA Financial Products Subledger version 1.0.
CVE-2019-0276 can lead to privilege escalation for authenticated users, allowing unauthorized access to sensitive data.
As of now, implementing access controls and monitoring user permissions can serve as a temporary workaround for CVE-2019-0276.