CVE-2019-0399: SAP Portfolio And Project Management

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user to discover accounting information of the Projects in Project dashboard, leading to Information Disclosure.

Affected products

  • SAP Portfolio And Project Management: version cprxrpm_500_702 only; version cprxrpm_600_740 only; version cprxrpm_610_740 only; version eppm_100 only; version s4core_102 only; version s4core_103 only

Published 2019-12-11. Last modified 2026-06-17.