Sap Se Sap Netweaver Process Integration vulnerabilities
13 known vulnerabilities affecting sap_se/sap_netweaver_process_integration.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM11
Vulnerabilities
Page 1 of 1
CVE-2024-28163MEDIUMCVSS 5.3v7.502024-03-12
CVE-2024-28163 [MEDIUM] CWE-732 CVE-2024-28163: Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.5
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
cvelistv5nvd
CVE-2023-37488MEDIUMCVSS 6.1vSAP_XIESR 7.50vSAP_XITOOL 7.50+1 more2023-08-08
CVE-2023-37488 [MEDIUM] CWE-79 CVE-2023-37488: In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user
In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scripting (XSS) attack. On successful exploitation the attacker can cause limited impact on confidentiality and integrity of the system.
cvelistv5nvd
CVE-2023-35872MEDIUMCVSS 6.5vSAP_XIAF 7.502023-07-11
CVE-2023-35872 [MEDIUM] CWE-306 CVE-2023-35872: The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does no
The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive informatio
cvelistv5nvd
CVE-2023-35873MEDIUMCVSS 6.5vSAP_XITOOL 7.502023-07-11
CVE-2023-35873 [MEDIUM] CWE-306 CVE-2023-35873: The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not
The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information
cvelistv5nvd
CVE-2019-0367MEDIUMCVSS 4.3fixed in 1.0fixed in 2.02019-10-08
CVE-2019-0367 [MEDIUM] CWE-862 CVE-2019-0367: SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform neces
SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check.
cvelistv5nvd
CVE-2019-0337MEDIUMCVSS 6.1fixed in 7.10fixed in 7.11+4 more2019-08-14
CVE-2019-0337 [MEDIUM] CWE-79 CVE-2019-0337: Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url thereby resulting in Reflected Cross-Site Scripting (XSS) vulnerability
cvelistv5nvd
CVE-2019-0316MEDIUMCVSS 4.8fixed in 7.20fixed in 7.10 to 7.11+4 more2019-06-14
CVE-2019-0316 [MEDIUM] CWE-79 CVE-2019-0316: SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31,
SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the
cvelistv5nvd
CVE-2019-0315HIGHCVSS 7.5fixed in 7.10 to 7.11fixed in 7.20+4 more2019-06-12
CVE-2019-0315 [HIGH] CVE-2019-0315: Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (ver
Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure.
cvelistv5nvd
CVE-2019-0312MEDIUMCVSS 5.3fixed in 7.10 to 7.11fixed in 7.20+4 more2019-06-12
CVE-2019-0312 [MEDIUM] CWE-306 CVE-2019-0312: Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.2
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of restrictive firewall and port set
cvelistv5nvd
CVE-2019-0305MEDIUMCVSS 4.3fixed in 7.10 to 7.11fixed in 7.2+4 more2019-06-12
CVE-2019-0305 [MEDIUM] CWE-1021 CVE-2019-0305: Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. Successful exploitation of this vulnerability leads
cvelistv5nvd
CVE-2019-0283HIGHCVSS 7.1fixed in from 7.10 to 7.11fixed in 7.30+3 more2019-04-10
CVE-2019-0283 [HIGH] CWE-290 CVE-2019-0283: SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40
SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML signatures and send arbitrary requests to the server via PI Axis adapter. These requests will be accepted by the PI Axis adapter even if the payload has been altered, especia
cvelistv5nvd
CVE-2019-0282MEDIUMCVSS 5.3fixed in from 7.10 to 7.11fixed in 7.30+3 more2019-04-10
CVE-2019-0282 [MEDIUM] CWE-287 CVE-2019-0282: Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 t
Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Java package and Java object names which can be misused by the attacker.
cvelistv5nvd
CVE-2019-0278MEDIUMCVSS 4.3fixed in 7.10 to 7.11fixed in 7.20+4 more2019-04-10
CVE-2019-0278 [MEDIUM] CVE-2019-0278: Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging
Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database tables used by the application, leading to information disclosure.
cvelistv5nvd