PT-2019-11228 · Sap · Sap Netweaver Process Integration
Publicado
2019-06-12
·
Atualizado
2020-08-24
·
CVE-2019-0312
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP NetWeaver Process Integration versions 7.10 through 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
Description:
The issue allows an attacker to access landscape information, including host names and ports, due to the lack of password protection on several web pages. This could be particularly problematic in the absence of restrictive firewall and port settings.
Recommendations:
For SAP NetWeaver Process Integration versions 7.10 through 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, consider implementing password protection for the affected web pages and ensure restrictive firewall and port settings are in place to minimize the risk of exploitation.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Netweaver Process Integration