SAP security note 2742758, "[CVE-2019-0282] Information Disclosure in NetWeaver PI Runtime Workbench", is a note released on 09.04.2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, the Runtime Workbench (RWB) allows an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
A patch for the Runtime Workbench is available. The Support Package stack guide can be found on the SAP Service Marketplace.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected components
- Basis Components > NetWeaver Process Integration (PI) > Integration Server > Runtime Workbench / Monitoring
Full note on SAP: SAP Support Launchpad note 2742758
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



