CVE Vulnerabilities

CVE-2019-0388

Authentication Bypass by Spoofing

Published: Nov 13, 2019 | Modified: Nov 20, 2019
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Ui Sap 2.0 (including) 2.0 (including)
Ui Sap 7.5 (including) 7.5 (including)
Ui Sap 7.51 (including) 7.51 (including)
Ui Sap 7.52 (including) 7.52 (including)
Ui Sap 7.53 (including) 7.53 (including)
Ui Sap 7.54 (including) 7.54 (including)

References