CVE-2019-0365
Last modified
CVE-2019-0365 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73 and KERNEL before versions 7.21, 7.49, 7.53, 7.73, 7.76 SAP GUI for Windows (BC-FES-GUI) before versions 7.5, 7.6, and SAP GUI for Java (BC-FES-JAV) before version 7.5, allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73 and KERNEL before versions 7.21, 7.49, 7.53, 7.73, 7.76 SAP GUI for Windows (BC-FES-GUI) before versions 7.5, 7.6, and SAP GUI for Java (BC-FES-JAV) before version 7.5, allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sap Kernel | 7.21 |
| Sap | Sap Kernel | 7.49 |
| Sap | Sap Kernel | 7.53 |
| Sap | Sap Kernel | 7.73 |
| Sap | Sap Kernel | 7.76 |
| Sap | Sap Kernel Krnl32nuc | 7.21 |
| Sap | Sap Kernel Krnl32nuc | 7.21ext |
| Sap | Sap Kernel Krnl32nuc | 7.22 |
| Sap | Sap Kernel Krnl32nuc | 7.22ext |
| Sap | Sap Kernel Krnl32uc | 7.21 |
| Sap | Sap Kernel Krnl32uc | 7.21ext |
| Sap | Sap Kernel Krnl32uc | 7.22 |
| Sap | Sap Kernel Krnl32uc | 7.22ext |
| Sap | Sap Kernel Krnl64nuc | 7.21 |
| Sap | Sap Kernel Krnl64nuc | 7.21ext |
| Sap | Sap Kernel Krnl64nuc | 7.22 |
| Sap | Sap Kernel Krnl64nuc | 7.22ext |
| Sap | Sap Kernel Krnl64uc | 7.21 |
| Sap | Sap Kernel Krnl64uc | 7.21ext |
| Sap | Sap Kernel Krnl64uc | 7.22 |
| Sap | Sap Kernel Krnl64uc | 7.22ext |
| Sap | Sap Kernel Krnl64uc | 7.49 |
| Sap | Sap Kernel Krnl64uc | 7.73 |
References
- https://launchpad.support.sap.com/#/notes/2786151Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2786151Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-0365?
How severe is CVE-2019-0365?
How do I fix CVE-2019-0365?
Are you affected by CVE-2019-0365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
