Vulnerability Description
Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Identity Management | 2.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2784307Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2784307Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032Vendor Advisory
FAQ
What is CVE-2019-0301?
CVE-2019-0301 is a vulnerability with a CVSS score of 8.8 (HIGH). Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only...
How severe is CVE-2019-0301?
CVE-2019-0301 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0301?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Identity Management.