Vulnerabilities > SAP > Advanced Business Application Programming Platform Kernel > High

DATE CVE VULNERABILITY TITLE RISK
2019-08-14 CVE-2019-0349 Missing Authorization vulnerability in SAP Advanced Business Application Programming Platform Kernel
SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute “Go to statement” without possessing the authorization S_DEVELOP DEBUG 02, resulting in Missing Authorization Check
network
low complexity
sap CWE-862
7.2
2019-03-12 CVE-2019-0270 Missing Authorization vulnerability in SAP products
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8
2019-02-15 CVE-2019-0255 Improper Input Validation vulnerability in SAP products
SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly.
network
low complexity
sap CWE-20
8.1