CVE Vulnerabilities

CVE-2019-0388

Authentication Bypass by Spoofing

Published: Nov 13, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

NameVendorStart VersionEnd Version
UiSap2.0 (including)2.0 (including)
UiSap7.5 (including)7.5 (including)
UiSap7.51 (including)7.51 (including)
UiSap7.52 (including)7.52 (including)
UiSap7.53 (including)7.53 (including)
UiSap7.54 (including)7.54 (including)

References