CVE-2019-0293
Last modified
CVE-2019-0293 is a vulnerability of currently unknown severity. Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sap Solution Manager System | 2008_1_700 |
| Sap | Sap Solution Manager System | 2008_1_710 |
| Sap | Sap Solution Manager System | 2008_1_740 |
References
- http://www.securityfocus.com/bid/108324Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2756625Permissions Required, Vendor Advisory
- http://www.securityfocus.com/bid/108324Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2756625Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-0293?
How severe is CVE-2019-0293?
How do I fix CVE-2019-0293?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-0283SAP NetWeaver Process Integration (Adapter Engine), fixed in…
- CVE-2019-0284SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) do…
- CVE-2019-0285The .NET SDK WebForm Viewer in SAP Crystal Reports for Visua…
- CVE-2019-0287Under certain conditions SAP BusinessObjects Business Intell…
- CVE-2019-0289Under certain conditions SAP BusinessObjects Business Intell…
- CVE-2019-0291Under certain conditions Solution Manager, version 7.2, allo…
- CVE-2019-0298SAP E-Commerce (Business-to-Consumer) application does not s…
- CVE-2019-0301Under certain conditions, it is possible to request the modi…
- CVE-2019-0303SAP BusinessObjects Business Intelligence Platform (Administ…
- CVE-2019-0304FTP Function of SAP NetWeaver AS ABAP Platform, versions- KR…
- CVE-2019-0305Java Server Pages (JSPs) provided by the SAP NetWeaver Proce…
- CVE-2019-0306SAP HANA Extended Application Services (advanced model), ver…
Are you affected by CVE-2019-0293?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
