MEDIUM
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected
Published Jun 12, 2019
5.3
MEDIUMCVSS 3.0
EPSS 1.14%
Description
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of restrictive firewall and port settings.
Affected products
-
- Version < 7.10 to 7.11StatusaffectedConstraints-
- Version < 7.20StatusaffectedConstraints-
- Version < 7.30StatusaffectedConstraints-
- Version < 7.31StatusaffectedConstraints-
- Version < 7.40StatusaffectedConstraints-
- Version < 7.50StatusaffectedConstraints-
- Version
-
- Version < 7.10 to 7.11StatusaffectedConstraints-
- Version < 7.30StatusaffectedConstraints-
- Version < 7.31StatusaffectedConstraints-
- Version < 7.40StatusaffectedConstraints-
- Version < 7.50StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SAP SE | SAP NetWeaver Process Integration(SAP XIESR) | n/a |
| |||||||||||||||||||||
| SAP SE | SAP NetWeaver Process Integration(SAP XITOOL) | n/a |
|
OR
- 7.10
- 7.11
- 7.20
- 7.30
- 7.31
- 7.40
- 7.50
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://launchpad.support.sap.com/#/notes/2744086 x_refsource_MISCPermissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://launchpad.support.sap.com/#/notes/2744086 | x_refsource_MISCPermissions RequiredVendor Advisory | |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Jun 12, 2019
Updated Aug 4, 2024
Reserved Nov 26, 2018
Link CVE-2019-0312
CISA Vulnrichment
Updated n/a