Privilege Escalation Vulnerability in SAP ERP and S4HANA Sales
CVE-2019-0386
6.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 13 November 2019
Summary
An identified vulnerability in SAP ERP Sales and S4HANA Sales relates to insufficient authorization checks during order processing for authenticated users. This loophole can potentially lead to unauthorized privilege escalation, allowing users to execute actions beyond their intended access levels. SAP has provided corrections in various versions for affected products to mitigate these risks. It is crucial for organizations using these systems to apply the relevant updates promptly to ensure their environment remains secure.
Affected Version(s)
S4HANA Sales (S4CORE) < 1.0 < 1.0
S4HANA Sales (S4CORE) < 1.01 < 1.01
S4HANA Sales (S4CORE) < 1.02 < 1.02
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved