« Volver al listado

CVE-2019-0389

Estado: ModificadaAlta (8.8)—

An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-0389",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver Application Server Java (J2EE-Framework)",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.1"
            },
            {
              "status": "affected",
              "version": "< 7.2"
            },
            {
              "status": "affected",
              "version": "< 7.3"
            },
            {
              "status": "affected",
              "version": "< 7.31"
            },
            {
              "status": "affected",
              "version": "< 7.4"
            },
            {
              "status": "affected",
              "version": "< 7.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-13T22:15:11.617",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2814357",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2814357",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise."
    },
    {
      "lang": "es",
      "value": "Un administrador de SAP NetWeaver Application Server Java (J2EE-Framework), (corregido en las versiones 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), puede cambiar los privilegios para todas o algunas funciones en Java Server, y permitir a usuarios ejecutar funciones, que no son permitidas ejecutar de otro modo."
    }
  ],
  "lastModified": "2026-06-17T02:08:17.580",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_java:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADA4F6C9-1CB3-4D82-AD9B-F0BD8203CC83"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_java:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADA6C739-64A9-4B97-90AE-8F8EF7025A10"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_java:7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FEABB91-A615-426E-A652-5390C1B21A03"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_java:7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AF1183A-3410-4E08-9473-3FF36C2096FE"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_java:7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFF5713B-C0C4-4062-BC6F-0BBD1E6FF620"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEAE6C2A-821F-4123-BD56-0FDADF9D63C8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}