Vulnerability Description
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of restrictive firewall and port settings.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Process Integration | 7.10 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2744086Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2744086Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242Vendor Advisory
FAQ
What is CVE-2019-0312?
CVE-2019-0312 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password pro...
How severe is CVE-2019-0312?
CVE-2019-0312 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0312?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Process Integration.