Vulnerabilites related to SAP SE - SAP Enterprise Financial Services (EA-FINSERV)
CVE-2018-2419 (GCVE-0-2018-2419)
Vulnerability from cvelistv5
Published
2018-05-09 20:00
Modified
2024-08-05 04:21
CWE
  • Missing Authorization Check
Summary
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacted products
Vendor Product Version
SAP SE SAP Enterprise Financial Services (SAPSCORE) Version: 1.11
Version: 1.12
Create a notification for this product.
   SAP SE SAP Enterprise Financial Services (S4CORE) Version: 1.01
Version: 1.02
Create a notification for this product.
   SAP SE SAP Enterprise Financial Services (EA-FINSERV) Version: 6.04
Version: 6.05
Version: 6.06
Version: 6.16
Version: 6.17
Version: 6.18
Version: 8.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T04:21:33.627Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/"
          },
          {
            "name": "104116",
            "tags": [
              "vdb-entry",
              "x_refsource_BID",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/104116"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://launchpad.support.sap.com/#/notes/2596627"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "SAP Enterprise Financial Services (SAPSCORE)",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "1.11"
            },
            {
              "status": "affected",
              "version": "1.12"
            }
          ]
        },
        {
          "product": "SAP Enterprise Financial Services (S4CORE)",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "1.01"
            },
            {
              "status": "affected",
              "version": "1.02"
            }
          ]
        },
        {
          "product": "SAP Enterprise Financial Services (EA-FINSERV)",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "6.04"
            },
            {
              "status": "affected",
              "version": "6.05"
            },
            {
              "status": "affected",
              "version": "6.06"
            },
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "affected",
              "version": "8.0"
            }
          ]
        }
      ],
      "datePublic": "2018-05-09T00:00:00",
      "descriptions": [
        {
          "lang": "en",
          "value": "SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Missing Authorization Check",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2018-05-10T09:57:01",
        "orgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
        "shortName": "sap"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/"
        },
        {
          "name": "104116",
          "tags": [
            "vdb-entry",
            "x_refsource_BID"
          ],
          "url": "http://www.securityfocus.com/bid/104116"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://launchpad.support.sap.com/#/notes/2596627"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cna@sap.com",
          "ID": "CVE-2018-2419",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "SAP Enterprise Financial Services (SAPSCORE)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "1.11"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "1.12"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "SAP Enterprise Financial Services (S4CORE)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "1.01"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "1.02"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "SAP Enterprise Financial Services (EA-FINSERV)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "6.04"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "6.05"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "6.06"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "6.16"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "6.17"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "6.18"
                          },
                          {
                            "version_affected": "=",
                            "version_value": "8.0"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "SAP SE"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges."
            }
          ]
        },
        "impact": {
          "cvss": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.0"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Missing Authorization Check"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/",
              "refsource": "CONFIRM",
              "url": "https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/"
            },
            {
              "name": "104116",
              "refsource": "BID",
              "url": "http://www.securityfocus.com/bid/104116"
            },
            {
              "name": "https://launchpad.support.sap.com/#/notes/2596627",
              "refsource": "MISC",
              "url": "https://launchpad.support.sap.com/#/notes/2596627"
            }
          ]
        },
        "source": {
          "discovery": "UNKNOWN"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
    "assignerShortName": "sap",
    "cveId": "CVE-2018-2419",
    "datePublished": "2018-05-09T20:00:00",
    "dateReserved": "2017-12-15T00:00:00",
    "dateUpdated": "2024-08-05T04:21:33.627Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2018-2484 (GCVE-0-2018-2484)
Vulnerability from cvelistv5
Published
2019-01-08 20:00
Modified
2024-08-05 04:21
Severity ?
CWE
  • Missing Authorization Check
Summary
SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacted products
Vendor Product Version
SAP SE SAP Enterprise Financial Services (SAPSCORE) Version: < 1.13
Version: < 1.14
Version: < 1.15
Create a notification for this product.
   SAP SE SAP Enterprise Financial Services (S4CORE) Version: < 1.01
Version: < 1.02
Version: < 1.03
Create a notification for this product.
   SAP SE SAP Enterprise Financial Services (EA-FINSERV) Version: < 1.10
Version: < 2.0
Version: < 5.0
Version: < 6.0
Version: < 6.03
Version: < 6.04
Version: < 6.05
Version: < 6.06
Version: < 6.16
Version: < 6.17
Version: < 6.18
Version: < 8.0
Create a notification for this product.
   SAP SE SAP Enterprise Financial Services (Bank/CFM) Version: < 4.63_20
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T04:21:33.945Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://launchpad.support.sap.com/#/notes/2662687"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=509151985"
          },
          {
            "name": "106477",
            "tags": [
              "vdb-entry",
              "x_refsource_BID",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/106477"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "SAP Enterprise Financial Services (SAPSCORE)",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 1.13"
            },
            {
              "status": "affected",
              "version": "\u003c 1.14"
            },
            {
              "status": "affected",
              "version": "\u003c 1.15"
            }
          ]
        },
        {
          "product": "SAP Enterprise Financial Services (S4CORE)",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 1.01"
            },
            {
              "status": "affected",
              "version": "\u003c 1.02"
            },
            {
              "status": "affected",
              "version": "\u003c 1.03"
            }
          ]
        },
        {
          "product": "SAP Enterprise Financial Services (EA-FINSERV)",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 1.10"
            },
            {
              "status": "affected",
              "version": "\u003c 2.0"
            },
            {
              "status": "affected",
              "version": "\u003c 5.0"
            },
            {
              "status": "affected",
              "version": "\u003c 6.0"
            },
            {
              "status": "affected",
              "version": "\u003c 6.03"
            },
            {
              "status": "affected",
              "version": "\u003c 6.04"
            },
            {
              "status": "affected",
              "version": "\u003c 6.05"
            },
            {
              "status": "affected",
              "version": "\u003c 6.06"
            },
            {
              "status": "affected",
              "version": "\u003c 6.16"
            },
            {
              "status": "affected",
              "version": "\u003c 6.17"
            },
            {
              "status": "affected",
              "version": "\u003c 6.18"
            },
            {
              "status": "affected",
              "version": "\u003c 8.0"
            }
          ]
        },
        {
          "product": "SAP Enterprise Financial Services (Bank/CFM)",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 4.63_20"
            }
          ]
        }
      ],
      "datePublic": "2019-01-08T00:00:00",
      "descriptions": [
        {
          "lang": "en",
          "value": "SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Missing Authorization Check",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2019-01-09T10:57:01",
        "orgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
        "shortName": "sap"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://launchpad.support.sap.com/#/notes/2662687"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=509151985"
        },
        {
          "name": "106477",
          "tags": [
            "vdb-entry",
            "x_refsource_BID"
          ],
          "url": "http://www.securityfocus.com/bid/106477"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cna@sap.com",
          "ID": "CVE-2018-2484",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "SAP Enterprise Financial Services (SAPSCORE)",
                      "version": {
                        "version_data": [
                          {
                            "version_name": "\u003c",
                            "version_value": "1.13"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "1.14"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "1.15"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "SAP Enterprise Financial Services (S4CORE)",
                      "version": {
                        "version_data": [
                          {
                            "version_name": "\u003c",
                            "version_value": "1.01"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "1.02"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "1.03"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "SAP Enterprise Financial Services (EA-FINSERV)",
                      "version": {
                        "version_data": [
                          {
                            "version_name": "\u003c",
                            "version_value": "1.10"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "2.0"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "5.0"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.0"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.03"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.04"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.05"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.06"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.16"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.17"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "6.18"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "8.0"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "SAP Enterprise Financial Services (Bank/CFM)",
                      "version": {
                        "version_data": [
                          {
                            "version_name": "\u003c",
                            "version_value": "4.63_20"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "SAP SE"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Missing Authorization Check"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://launchpad.support.sap.com/#/notes/2662687",
              "refsource": "MISC",
              "url": "https://launchpad.support.sap.com/#/notes/2662687"
            },
            {
              "name": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=509151985",
              "refsource": "MISC",
              "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=509151985"
            },
            {
              "name": "106477",
              "refsource": "BID",
              "url": "http://www.securityfocus.com/bid/106477"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
    "assignerShortName": "sap",
    "cveId": "CVE-2018-2484",
    "datePublished": "2019-01-08T20:00:00",
    "dateReserved": "2017-12-15T00:00:00",
    "dateUpdated": "2024-08-05T04:21:33.945Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}