Back to search
CVE-2019-0386
Published: Nov 13, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP ERP Sales (SAP_APPL) | affected < 6.0affected < 6.02affected < 6.03affected < 6.04affected < 6.05+4 more versions |
SAP SE | S4HANA Sales (S4CORE) | affected < 1.0affected < 1.01affected < 1.02affected < 1.03affected < 1.04 |
References
https://launchpad.support.sap.com/#/notes/2840520
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now