« Volver al listado

CVE-2019-0314

Estado: ModificadaMedia (5.5)—

SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-0314",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP Work Manager",
          "versions": [
            {
              "status": "affected",
              "version": "< 6.3"
            },
            {
              "status": "affected",
              "version": "< 6.4"
            },
            {
              "status": "affected",
              "version": "< 6.5"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP Inventory Manager",
          "versions": [
            {
              "status": "affected",
              "version": "< 4.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-06-12T17:29:03.670",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2793805",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2793805",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service."
    },
    {
      "lang": "es",
      "value": "El administrador SAP work  versiones  6.3, 6.4, 6.5 y el administrador SAP Inventory, versiones 4.3, permite a un atacante evitar usuarios legítimos un servicio,  colgando o  inundando el servicio"
    }
  ],
  "lastModified": "2026-06-17T02:08:09.847",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:work_manager:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9CF5CD6-1116-4BEA-B584-92D052130D43"
            },
            {
              "criteria": "cpe:2.3:a:sap:work_manager:6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BAFFFB3-B367-4B2F-94CB-67B869D020C3"
            },
            {
              "criteria": "cpe:2.3:a:sap:work_manager:6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA4EADA1-2F4E-4143-9ACC-A49AF2962013"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:inventory_manager:4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D6892BD-584C-4990-8C85-AD17F19EBF8E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}