CVE-2019-0293 Vulnerability Details

  /     /     /  

CVE-2019-0293 Metadata Quick Info

CVE Published: 14/05/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: sap | Vendor: SAP SE | Product: SAP Solution Manager system (ST-PI)
Status : PUBLISHED

CVE-2019-0293 Description

Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Missing Authorization Check
Source: SAP SE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).