First published: Wed Jun 12 2019(Updated: )
Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Process Integration | =7.10 | |
SAP NetWeaver Process Integration | =7.11 | |
SAP NetWeaver Process Integration | =7.20 | |
SAP NetWeaver Process Integration | =7.30 | |
SAP NetWeaver Process Integration | =7.31 | |
SAP NetWeaver Process Integration | =7.40 | |
SAP NetWeaver Process Integration | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0315 is high with a CVSS score of 7.5.
Versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver Process Integration are affected.
Under certain conditions, an attacker can access passwords used in FTP channels via the PI Integration Builder Web UI of SAP NetWeaver Process Integration.
You can find more information about CVE-2019-0315 at the following references: [Launchpad Support Note](https://launchpad.support.sap.com/#/notes/2755438) and [SAP Wiki Page](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242).
Apply the relevant patches provided by SAP to mitigate the vulnerability in the affected versions of SAP NetWeaver Process Integration.