CVE-2019-0315: High severity sap netweaver process integration vulnerability
Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAPXIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAPXITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAPXIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0315?
The severity of CVE-2019-0315 is high with a CVSS score of 7.5.
Which versions of SAP NetWeaver Process Integration are affected by CVE-2019-0315?
Versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver Process Integration are affected.
How can an attacker exploit CVE-2019-0315?
Under certain conditions, an attacker can access passwords used in FTP channels via the PI Integration Builder Web UI of SAP NetWeaver Process Integration.
What is the reference for more information on CVE-2019-0315?
You can find more information about CVE-2019-0315 at the following references: [Launchpad Support Note](https://launchpad.support.sap.com/#/notes/2755438) and [SAP Wiki Page](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242).
How can I mitigate the vulnerability CVE-2019-0315?
Apply the relevant patches provided by SAP to mitigate the vulnerability in the affected versions of SAP NetWeaver Process Integration.