CVE-2019-0312: Medium severity sap netweaver process integration vulnerability
Several web pages provided SAP NetWeaver Process Integration (versions: SAPXIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAPXITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of restrictive firewall and port settings.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-0312?
CVE-2019-0312 is a vulnerability in SAP NetWeaver Process Integration that allows unauthorized access to landscape information.
What versions of SAP NetWeaver Process Integration are affected by CVE-2019-0312?
Versions SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50, and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, and 7.50 are affected.
What is the severity of CVE-2019-0312?
CVE-2019-0312 has a severity rating of 5.3, which is considered medium.
How can an attacker exploit CVE-2019-0312?
An attacker can exploit CVE-2019-0312 by accessing unprotected web pages to gather landscape information like host names and ports.
Are there any fixes or mitigations available for CVE-2019-0312?
Yes, SAP has released security notes and recommendations to address the vulnerability. Please refer to the SAP support page for more information.