CVE-2019-0383 is a high-severity authorization bypass vulnerability in SAP Treasury and Risk Management (S4CORE) and SAP Enterprise Extension Financial Services. An authenticated attacker can exploit this flaw to escalate privileges due to insufficient authorization checks. The vulnerability has a CVSS score of 8.8 (High), indicating it can be exploited over a network with low complexity by a low-privileged user, leading to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has received some community and media attention. Organizations using affected SAP products should apply the provided patches to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:sap:enterprise_extension_financial_services:6.0:*:*:*:*:*:*:* | ||
6.03CPE matchmatch criteria | cpe:2.3:a:sap:enterprise_extension_financial_services:6.03:*:*:*:*:*:*:* | ||
6.04CPE matchmatch criteria | cpe:2.3:a:sap:enterprise_extension_financial_services:6.04:*:*:*:*:*:*:* | ||
6.05CPE matchmatch criteria | cpe:2.3:a:sap:enterprise_extension_financial_services:6.05:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:a:sap:enterprise_extension_financial_services:6.06:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.