First published: Wed Aug 14 2019(Updated: )
SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute “Go to statement” without possessing the authorization S_DEVELOP DEBUG 02, resulting in Missing Authorization Check
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Advanced Business Application Programming Platform Kernel | =7.21 | |
Sap Advanced Business Application Programming Platform Kernel | =7.21ext | |
Sap Advanced Business Application Programming Platform Kernel | =7.22 | |
Sap Advanced Business Application Programming Platform Kernel | =7.22ext | |
Sap Advanced Business Application Programming Platform Kernel | =7.49 | |
Sap Advanced Business Application Programming Platform Kernel | =7.53 | |
Sap Advanced Business Application Programming Platform Kernel | =7.73 | |
Sap Advanced Business Application Programming Platform Kernel | =7.75 | |
Sap Advanced Business Application Programming Platform Kernel | =7.76 | |
Sap Advanced Business Application Programming Platform Kernel | =7.77 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0349 has a medium severity rating due to potential unauthorized access risks.
To fix CVE-2019-0349, update the affected versions of SAP Kernel to the latest patched version provided by SAP.
CVE-2019-0349 affects various versions of SAP Kernel including 7.21, 7.22, 7.49, 7.53, 7.73, 7.75, 7.76, and 7.77.
CVE-2019-0349 is an SAP Kernel vulnerability that allows users to execute unauthorized commands within the ABAP Debugger.
There have been indications that CVE-2019-0349 may be a target for exploitation, making timely updates crucial.