Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:*:*:*:*:*:*:*:*", "matchCriteriaId": "4998F531-ED39-46D4-BA62-466BD37C8873", "versionEndIncluding": "7.02", "versionStartIncluding": "7.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:*:*:*:*:*:*:*:*", "matchCriteriaId": "C31EF66D-DB32-4352-8824-6630B8C61D47", "versionEndIncluding": "7.53", "versionStartIncluding": "7.50", "vulnerable": true}, {"criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:7.30:*:*:*:*:*:*:*", "matchCriteriaId": "FB5E17A3-C1F1-4FB9-8AB2-347C0429E29A", "vulnerable": true}, {"criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:7.31:*:*:*:*:*:*:*", "matchCriteriaId": "6F65C175-29C0-4AC0-887F-46A222FAAF10", "vulnerable": true}, {"criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:7.40:*:*:*:*:*:*:*", "matchCriteriaId": "C0C8BB3C-64ED-456B-93A8-B18F30338BD6", "vulnerable": true}, {"criteria": "cpe:2.3:a:sap:netweaver_as_abap:*:*:*:*:*:*:*:*", "matchCriteriaId": "01C3F7F6-3B1D-40C8-B305-8CEC6DEFA851", "versionEndIncluding": "7.11", "versionStartIncluding": "7.10", "vulnerable": true}, {"criteria": "cpe:2.3:a:sap:netweaver_as_abap:*:*:*:*:*:*:*:*", "matchCriteriaId": "341EDF6B-976B-46C4-BF35-CFB341C844F0", "versionEndIncluding": "7.75", "versionStartIncluding": "7.74", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges."}, {"lang": "es", "value": "La funcionalidad de personalizaci\u00f3n de SAP NetWeaver AS ABAP Platform (solucionado en versiones desde la 7.0 hasta la 7.02, desde la 7.10 hasta la 7.11, la 7.30, 7.31, 7.40, desde la 7.50 hasta la 7.53 y desde la 7.74 hasta la 7.75) no realiza las comprobaciones necesarias de autorizaci\u00f3n para un usuario autenticado, lo que resulta en un escalado de privilegios."}], "id": "CVE-2019-0257", "lastModified": "2024-11-21T04:16:35.483", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 6.5, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 8.0, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2019-02-15T18:29:01.037", "references": [{"source": "cna@sap.com", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securityfocus.com/bid/106999"}, {"source": "cna@sap.com", "tags": ["Permissions Required", "Vendor Advisory"], "url": "https://launchpad.support.sap.com/#/notes/2728839"}, {"source": "cna@sap.com", "tags": ["Broken Link", "Vendor Advisory"], "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securityfocus.com/bid/106999"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Permissions Required", "Vendor Advisory"], "url": "https://launchpad.support.sap.com/#/notes/2728839"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Broken Link", "Vendor Advisory"], "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943"}], "sourceIdentifier": "cna@sap.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-862"}], "source": "nvd@nist.gov", "type": "Primary"}]}