CVE-2018-2419

medium

Description

SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

References

https://launchpad.support.sap.com/#/notes/2596627

https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/

http://www.securityfocus.com/bid/104116

Details

Source: Mitre, NVD

Published: 2018-05-09

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00189