CVE-2019-0312
Published: Jun 12, 2019
Modified: Aug 4, 2024
Description
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of restrictive firewall and port settings.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP NetWeaver Process Integration(SAP_XIESR) | affected < 7.10 to 7.11affected < 7.20affected < 7.30affected < 7.31affected < 7.40+1 more versions |
SAP SE | SAP NetWeaver Process Integration(SAP_XITOOL) | affected < 7.10 to 7.11affected < 7.30affected < 7.31affected < 7.40affected < 7.50 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now