Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0301 Privilege Escalation in SAP Identity Management REST Interface Version 2, SAP security note 2784307

SAP Note 2784307

SAP security note 2784307, "[CVE-2019-0301] Privilege Escalation in SAP Identity Management REST Interface Version 2". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, it is possible to request the modification of role or privilege assignments through the SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing.

Impacts of this vulnerability include:

  • Privilege escalation for the user for connected systems to SAP Identity Management.
  • Loss of confidentiality and integrity depending on the connected systems to SAP Identity Management.

Solution

A programming error was fixed in the SAP Identity Management REST Interface Version 2. To resolve this issue:

  • Apply the attached patch provided in the Support Packages & Patches section of this SAP Note.
  • Ensure all components are updated to the corresponding service pack level before applying the patch.

Reason and prerequisites

You are using SAP Identity Management 8.0 SP06.

CVSS

Score 8.4 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

References

  • CVE-2019-0301 Details

Affected components

  • SAP Identity Management 8.0 SP06

Full note on SAP: SAP Support Launchpad note 2784307

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More