Privilege Escalation Vulnerability in SAP ERP and S4HANA Sales
CVE-2019-0386

6.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 November 2019

Summary

An identified vulnerability in SAP ERP Sales and S4HANA Sales relates to insufficient authorization checks during order processing for authenticated users. This loophole can potentially lead to unauthorized privilege escalation, allowing users to execute actions beyond their intended access levels. SAP has provided corrections in various versions for affected products to mitigate these risks. It is crucial for organizations using these systems to apply the relevant updates promptly to ensure their environment remains secure.

Affected Version(s)

S4HANA Sales (S4CORE) < 1.0 < 1.0

S4HANA Sales (S4CORE) < 1.01 < 1.01

S4HANA Sales (S4CORE) < 1.02 < 1.02

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.