CVE Vulnerabilities

CVE-2019-0389

Published: Nov 13, 2019 | Modified: Aug 24, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.

Affected Software

Name Vendor Start Version End Version
Netweaver_application_server_java Sap 7.1 (including) 7.1 (including)
Netweaver_application_server_java Sap 7.2 (including) 7.2 (including)
Netweaver_application_server_java Sap 7.3 (including) 7.3 (including)
Netweaver_application_server_java Sap 7.4 (including) 7.4 (including)
Netweaver_application_server_java Sap 7.5 (including) 7.5 (including)
Netweaver_application_server_java Sap 7.31 (including) 7.31 (including)

References