Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0312 Information Disclosure in SAP NetWeaver Process Integration, SAP security note 2744086

SAP Note 2744086

SAP security note 2744086, "[CVE-2019-0312] Information Disclosure in SAP NetWeaver Process Integration", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, SAP NetWeaver Process Integration (PI) allows an attacker to access information that should be restricted. This vulnerability arises because several web pages provided by PI are not password protected. If the PI system is exposed to an external network without proper firewall and port restrictions (as detailed in SAP Note 1451753), an attacker could obtain landscape information such as host names, ports, and other technical data. It’s important to note that confidential data like usernames and passwords are not affected by this vulnerability.

  • Loss of information and system configuration confidentiality.
  • Facilitation of information gathering for further exploits and attacks.

Solution

This issue has been addressed by implementing appropriate access protections on all relevant pages displaying technical data. To mitigate this vulnerability, you should deploy the Support Packages and Patches referenced in SAP Security Note 2744086.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2744086

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More