Privilege Escalation in SAP Enterprise Financial Services by SAP
CVE-2018-2419

3.7LOW

Summary

The vulnerability involves a failure in SAP Enterprise Financial Services to enforce necessary authorization checks for authenticated users. This weakness can potentially allow attackers to escalate their privileges and gain unauthorized access to sensitive functionalities and data. The affected versions of SAP products include various iterations of SAPSCORE and EA-FINSERV, emphasizing the need for immediate patching and security measures to mitigate these risks.

Affected Version(s)

SAP Enterprise Financial Services (EA-FINSERV) 6.04

SAP Enterprise Financial Services (EA-FINSERV) 6.05

SAP Enterprise Financial Services (EA-FINSERV) 6.06

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.