CVE-2019-0399

MEDIUM

SAP Portfolio and Project Management - Information Disclosure in Project Dashboard

Title source: llm
STIX 2.1

Description

SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user to discover accounting information of the Projects in Project dashboard, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required x_refsource_confirm
https://launchpad.support.sap.com/#/notes/2803554

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (6)
sap/portfolio_and_project_management cprxrpm_500_702
sap/portfolio_and_project_management cprxrpm_600_740
sap/portfolio_and_project_management cprxrpm_610_740
sap/portfolio_and_project_management eppm_100
sap/portfolio_and_project_management s4core_102
sap/portfolio_and_project_management s4core_103
Published Dec 11, 2019
Tracked Since Feb 18, 2026