PT-2019-11228 · Sap · Sap Netweaver Process Integration
Published
2019-06-12
·
Updated
2020-08-24
·
CVE-2019-0312
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP NetWeaver Process Integration versions 7.10 through 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
Description:
The issue allows an attacker to access landscape information, including host names and ports, due to the lack of password protection on several web pages. This could be particularly problematic in the absence of restrictive firewall and port settings.
Recommendations:
For SAP NetWeaver Process Integration versions 7.10 through 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, consider implementing password protection for the affected web pages and ensure restrictive firewall and port settings are in place to minimize the risk of exploitation.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver Process Integration