VYPR
High severity8.8NVD Advisory· Published Feb 15, 2019· Updated Jun 17, 2026

CVE-2019-0257

CVE-2019-0257

Description

Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Affected products

7
  • cpe:2.3:a:sap:netweaver_application_server_abap:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:sap:netweaver_application_server_abap:*:*:*:*:*:*:*:*range: >=7.0,<=7.02
    • cpe:2.3:a:sap:netweaver_application_server_abap:7.30:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver_application_server_abap:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver_application_server_abap:7.40:*:*:*:*:*:*:*
  • cpe:2.3:a:sap:netweaver_as_abap:*:*:*:*:*:*:*:*
    Range: >=7.10,<=7.11
  • Range: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 to 7.53, 7.74 to 7.75
  • SAP SE/ABAP Platform(SAP Basis)v5
    Range: < from 7.0 to 7.02

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.