Vulnerability Name: | CVE-2019-0367 (CCN-168936) | ||||||||||||
Assigned: | 2018-11-26 | ||||||||||||
Published: | 2019-10-08 | ||||||||||||
Updated: | 2019-10-10 | ||||||||||||
Summary: | SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check. | ||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-862 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-0367 Source: XF Type: UNKNOWN sap-cve20190367-sec-bypass(168936) Source: CCN Type: SAP Web site SAP Support Note 2805777 Source: MISC Type: Permissions Required https://launchpad.support.sap.com/#/notes/2805777 Source: CCN Type: SAP Security Patch Day - October 2019 SAP Security Patch Day - October 2019 Source: CONFIRM Type: Vendor Advisory https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |