SAP security note 2755438, "[CVE-2019-0315] Information Disclosure in Integration Builder Framework of SAP NetWeaver Process Integration", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, the PI Integration Builder Web UI of SAP NetWeaver Process Integration allows an attacker to access restricted information. This can lead to:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
This vulnerability has been addressed in the Support Packages and Patches referenced in this SAP Security Note.
Reason and prerequisites
A user with PI Administrator rights is required to access the vulnerable web page. The exposed data pertains to PI communication channels used by the Adapter Framework.
CVSS
Score 5.8 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Affected components
- BC-XI-IBF-UI: 7.10 to 7.50
Full note on SAP: SAP Support Launchpad note 2755438
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
