PT-2019-11228 · Sap · Sap Netweaver Process Integration

Published

2019-06-12

·

Updated

2020-08-24

·

CVE-2019-0312

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver Process Integration versions 7.10 through 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
Description: The issue allows an attacker to access landscape information, including host names and ports, due to the lack of password protection on several web pages. This could be particularly problematic in the absence of restrictive firewall and port settings.
Recommendations: For SAP NetWeaver Process Integration versions 7.10 through 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, consider implementing password protection for the affected web pages and ensure restrictive firewall and port settings are in place to minimize the risk of exploitation.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-0312

Affected Products

Sap Netweaver Process Integration