CVE-2019-0312

Severity
5.3MEDIUM
EPSS
0.2%
top 60.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 12
Latest updateMay 24

Description

Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of restrictive firewall and port settings.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-6rqj-rwr9-wwm7: Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 72022-05-24
CVEList
CVE-2019-0312: Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 72019-06-12
CVE-2019-0312 (MEDIUM CVSS 5.3) | Several web pages provided SAP NetW | cvebase.io