SAP security note 2744086, "[CVE-2019-0312] Information Disclosure in SAP NetWeaver Process Integration", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, SAP NetWeaver Process Integration (PI) allows an attacker to access information that should be restricted. This vulnerability arises because several web pages provided by PI are not password protected. If the PI system is exposed to an external network without proper firewall and port restrictions (as detailed in SAP Note 1451753), an attacker could obtain landscape information such as host names, ports, and other technical data. It’s important to note that confidential data like usernames and passwords are not affected by this vulnerability.
- Loss of information and system configuration confidentiality.
- Facilitation of information gathering for further exploits and attacks.
Solution
This issue has been addressed by implementing appropriate access protections on all relevant pages displaying technical data. To mitigate this vulnerability, you should deploy the Support Packages and Patches referenced in SAP Security Note 2744086.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2744086
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
