Sap Se Sap Manufacturing Integration And Intelligence vulnerabilities
2 known vulnerabilities affecting sap_se/sap_manufacturing_integration_and_intelligence.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2021-21480HIGHCVSS 8.8fixed in 15.1fixed in 15.2+2 more2021-03-09
CVE-2021-21480 [HIGH] CWE-94 CVE-2021-21480: SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Compos
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users having at least SAP_XMII Developer role, malicious content in the dashboard gets
cvelistv5nvd
CVE-2019-0267HIGHCVSS 8.8fixed in 15.0fixed in 15.1+1 more2019-02-15
CVE-2019-0267 [HIGH] CWE-352 CVE-2019-0267: SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet)
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.
cvelistv5nvd