Information Disclosure Vulnerability in SAP NetWeaver Process Integration
CVE-2019-0315

7.5HIGH

Summary

The PI Integration Builder Web UI of SAP NetWeaver Process Integration may allow unauthorized access to sensitive information, such as passwords used in FTP channels. This could enable an attacker to exploit the information for malicious purposes. Affected versions include SAP_XIESR, SAP_XITOOL, and SAP_XIPCK across various iterations. Organizations utilizing these components should assess their exposure and implement measures to safeguard their systems.

Affected Version(s)

SAP NetWeaver Process Integration(SAP_XIESR) < 7.10 to 7.11 < 7.10 to 7.11

SAP NetWeaver Process Integration(SAP_XIESR) < 7.20 < 7.20

SAP NetWeaver Process Integration(SAP_XIESR) < 7.30 < 7.30

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.