CVE-2019-17495
In SAP Software existieren mehrere Schwachstellen. Diese Fehler existieren in verschiedenen Produkten, einschließlich dem Business Client, Netweaver, BusinessObjects und mehr, aufgrund fehlender Autorisierungsprüfungen, fehlerhafter Eingabevalidierung oder eines Relative Path Overwrite-Problems. Ein entfernter Angreifer kann diese Schwachstellen ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, oder vertrauliche Informationen offenzulegen. Einige dieser Schwachstellen erfordern entweder Benutzerinteraktion oder Privilegien für eine erfolgreiche Ausnutzung.
EPSS 11.56% · 93.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP | SAP Software | |
| EMC | EMC Avamar | |
| IBM | IBM Tivoli Network Manager 4.2.0 | |
| Oracle | Oracle Construction and Engineering |
Exploit Intelligence
- CIRCL seen: CVE-2019-17495 (circl-sighting)
- https://www.oracle.com/security-alerts/cpuoct2020.html (circl)
- https://github.com/swagger-api/swagger-ui/releases/tag/v3.23.11 (circl)
- https://www.oracle.com/security-alerts/cpuApr2021.html (circl)
- [airflow-commits] 20210920 [GitHub] [airflow] boring-cyborg[bot] commented on issue #18383: CVE-2019-17495 for swagger-ui (circl)
- [airflow-commits] 20210920 [GitHub] [airflow] beltran-rubo opened a new issue #18383: CVE-2019-17495 for swagger-ui (circl)
- [airflow-commits] 20210920 [GitHub] [airflow] uranusjr commented on issue #18383: CVE-2019-17495 for swagger-ui (circl)
- [airflow-commits] 20210921 [GitHub] [airflow] beltran-rubo commented on issue #18383: CVE-2019-17495 for swagger-ui (circl)
- [airflow-commits] 20210921 [GitHub] [airflow] beltran-rubo closed issue #18383: CVE-2019-17495 for swagger-ui (circl)
- https://www.oracle.com/security-alerts/cpujan2022.html (circl)
…and 18 more exploits
Timeline
- CVE Published
- Apr 14, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Nov 8, 2023 EPSS Score
- Dec 17, 2024 EPSS Score
- Mar 19, 2025 EPSS Score
- Mar 23, 2025 EPSS Score
- Mar 24, 2025 EPSS Score
- Mar 28, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Apr 30, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2020/wid-sec-w-2023-1048.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1048 advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html#AppendixPVA advisory
- https://www.ibm.com/support/pages/node/6985225 advisory
- https://www.dell.com/support/kbdoc/000221770/dsa-2024-= advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1107.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1107 advisory
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news/may-2024.html advisory