Information Disclosure Vulnerability in SAP NetWeaver Process Integration
CVE-2019-0315
7.5HIGH
Key Information:
- Vendor
- SAP
- Status
- Vendor
- CVE Published:
- 12 June 2019
Summary
The PI Integration Builder Web UI of SAP NetWeaver Process Integration may allow unauthorized access to sensitive information, such as passwords used in FTP channels. This could enable an attacker to exploit the information for malicious purposes. Affected versions include SAP_XIESR, SAP_XITOOL, and SAP_XIPCK across various iterations. Organizations utilizing these components should assess their exposure and implement measures to safeguard their systems.
Affected Version(s)
SAP NetWeaver Process Integration(SAP_XIESR) < 7.10 to 7.11 < 7.10 to 7.11
SAP NetWeaver Process Integration(SAP_XIESR) < 7.20 < 7.20
SAP NetWeaver Process Integration(SAP_XIESR) < 7.30 < 7.30
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved