CVE-2019-0293 is a missing authorization check vulnerability affecting SAP Solution Manager systems (ST-PI versions 2008_1_700, 2008_1_710, and 740). This flaw allows an authenticated attacker to escalate privileges and access sensitive information on RFC destinations within managed systems and the Solution Manager itself. With a CVSS score of 6.5 (Medium), it has a low attack complexity and can lead to high confidentiality impact without requiring user interaction. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2008_1_700CPE matchmatch criteria | cpe:2.3:a:sap:sap_solution_manager_system:2008_1_700:*:*:*:*:*:*:* | ||
2008_1_710CPE matchmatch criteria | cpe:2.3:a:sap:sap_solution_manager_system:2008_1_710:*:*:*:*:*:*:* | ||
2008_1_740CPE matchmatch criteria | cpe:2.3:a:sap:sap_solution_manager_system:2008_1_740:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.