First published: Tue Oct 08 2019(Updated: )
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Process Integration | =1.0 | |
SAP NetWeaver Process Integration | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0379 is rated as high severity due to the potential for unauthorized access caused by a missing authentication check.
To fix CVE-2019-0379, ensure that the default security provider remains unchanged from BouncyCastle and implement proper authentication checks.
CVE-2019-0379 affects SAP Process Integration versions 1.0 and 2.0.
An attacker exploiting CVE-2019-0379 could gain unauthorized access to sensitive business data.
Disabling or reverting to the default security provider can serve as a temporary workaround for CVE-2019-0379.