Medium severity6.5NVD Advisory· Published May 14, 2019· Updated Jun 17, 2026
CVE-2019-0293
CVE-2019-0293
Description
Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).
Affected products
6- SAP SE/SAP Solution Manager system (ST-PI)v5Range: < 2008_1_700
- Range: <2008_1_700, <2008_1_710, <740
cpe:2.3:a:sap:sap_solution_manager_system:2008_1_700:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sap:sap_solution_manager_system:2008_1_700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_solution_manager_system:2008_1_710:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_solution_manager_system:2008_1_740:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/108324nvdThird Party AdvisoryVDB Entry
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.