Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0267 Cross site request forgery in implementation of Manufacturing Integration and Intelligence, SAP security note 2686535

Description

MII Illuminator Servlet currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.

Available fix and Supported packages

  • XMII | 15.0 | 15.0
  • XMII | 15.1 | 15.1
  • XMII | 15.2 | 15.2
  • MII_ADMIN 15.0 | SP009 | 000005
  • MII_ADMIN 15.1 | SP006 | 000008
  • MII_ADMIN 15.2 | SP000 | 000004
  • XMII 15.0 | SP009 | 000010
  • XMII 15.1 | SP006 | 000023
  • XMII 15.2 | SP000 | 000012

Affected component

    MFG-MII
    SAP Manufacturing Integration and Intelligence

CVSS

Score: 6.3
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2686535

TAGS

#MII
#Illuminator
#XSRF
#&160-CVE-2019-0267

Explore More

SAP Security Patch Day – September 2025

SAP has released its September 2025 security patch package containing 26 security notes addressing critical vulnerabilities across enterprise SAP environments. This release