Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0315 Information Disclosure in Integration Builder Framework of SAP NetWeaver Process Integration, SAP security note 2755438

SAP Note 2755438

SAP security note 2755438, "[CVE-2019-0315] Information Disclosure in Integration Builder Framework of SAP NetWeaver Process Integration", is a note. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-XI-IBF-UI

Description

Symptom

Under certain conditions, the PI Integration Builder Web UI of SAP NetWeaver Process Integration allows an attacker to access restricted information. This can lead to:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

This vulnerability has been addressed in the Support Packages and Patches referenced in this SAP Security Note.

Reason and prerequisites

A user with PI Administrator rights is required to access the vulnerable web page. The exposed data pertains to PI communication channels used by the Adapter Framework.

CVSS

Score 5.8 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected components

  • BC-XI-IBF-UI: 7.10 to 7.50

Full note on SAP: SAP Support Launchpad note 2755438

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More