CVE-2019-0280: High severity sap treasury and risk management (ea-finserv) vulnerability
SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects TDEALDP and TDEALPD , resulting in escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0280?
CVE-2019-0280 is considered a critical vulnerability due to its potential for privilege escalation.
How does CVE-2019-0280 affect SAP Treasury and Risk Management?
CVE-2019-0280 affects SAP Treasury and Risk Management by allowing unauthorized access to sensitive operations due to insufficient authorization checks.
What versions of SAP are affected by CVE-2019-0280?
CVE-2019-0280 affects multiple versions of SAP Treasury and Risk Management, specifically versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, and 8.0.
How can I fix CVE-2019-0280?
To fix CVE-2019-0280, it is recommended to apply the security patches provided by SAP for the affected software versions.
What types of attacks can exploit CVE-2019-0280?
CVE-2019-0280 can be exploited through privilege escalation attacks, where an attacker can gain unauthorized access to deal management functions within SAP.