Vulnerability Description
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Enterprise Extension Financial Services | 6.0 |
| Sap | Treasury And Risk Management \(S4Core\) | 1.01 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2819170Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2819170Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390Vendor Advisory
FAQ
What is CVE-2019-0383?
CVE-2019-0383 is a vulnerability with a CVSS score of 8.8 (HIGH). Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not per...
How severe is CVE-2019-0383?
CVE-2019-0383 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0383?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Enterprise Extension Financial Services, Sap Treasury And Risk Management \(S4Core\).