Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-0349

Опубликовано: 14 авг. 2019
Источник: nvd
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute “Go to statement” without possessing the authorization S_DEVELOP DEBUG 02, resulting in Missing Authorization Check

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.21:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.21ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.22:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.22ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.49:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.53:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.73:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.75:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.76:*:*:*:*:*:*:*
cpe:2.3:a:sap:advanced_business_application_programming_platform_kernel:7.77:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00354
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute ?Go to statement? without possessing the authorization S_DEVELOP DEBUG 02, resulting in Missing Authorization Check

CVSS3: 7.2
fstec
больше 6 лет назад

Уязвимость отладчика ABAP Debugger, вызванная недостатками процедуры авторизации, позволяющая нарушителю выполнить команду «Go to statement» без процедуры авторизации

EPSS

Процентиль: 57%
0.00354
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-862