CVE-2019-0399: SAP Portfolio And Project Management
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user to discover accounting information of the Projects in Project dashboard, leading to Information Disclosure.
Affected products
- SAP Portfolio And Project Management: version cprxrpm_500_702 only; version cprxrpm_600_740 only; version cprxrpm_610_740 only; version eppm_100 only; version s4core_102 only; version s4core_103 only
Published 2019-12-11. Last modified 2026-06-17.