Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0399 Potential Information Disclosure in SAP Portfolio and Project Management, SAP security note 2803554

SAP Note 2803554

SAP security note 2803554, "[CVE-2019-0399] Potential Information Disclosure in SAP Portfolio and Project Management". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user without necessary authorization can discover accounting information of the Projects in the Project dashboard.

Solution

Implement the attached correction instructions.

Reason and prerequisites

Accounting information can be disclosed by the PPM application. The information may be used by an attacker to obtain cost-related data about the project.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected components

  • S4CORE: Versions 102, 103
  • EPPM: Version 100
  • CPRXRPM: Versions 500_702, 600_740, 610_740

Full note on SAP: SAP Support Launchpad note 2803554

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More