Vulnerability Description
ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary authorization checks in all circumstances for an authenticated user, resulting in escalation of privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Application Software Integrated Solution | >= 7.00, <= 7.02 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2753629Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2753629Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114Vendor Advisory
FAQ
What is CVE-2019-0279?
CVE-2019-0279 is a vulnerability with a CVSS score of 8.8 (HIGH). ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do n...
How severe is CVE-2019-0279?
CVE-2019-0279 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0279?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business Application Software Integrated Solution.