CVE-2019-0293

MEDIUM

SAP Solution Manager System - Missing Authorization for RFC Destination Access

Title source: llm
STIX 2.1

Description

Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).

References (3)

Core 3
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2756625
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108324

Scores

CVSS v3 6.5
EPSS 0.0021
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-862
Status published
Products (3)
sap/sap_solution_manager_system 2008_1_700
sap/sap_solution_manager_system 2008_1_710
sap/sap_solution_manager_system 2008_1_740
Published May 14, 2019
Tracked Since Feb 18, 2026