« Volver al listado

CVE-2019-0315

Estado: ModificadaAlta (7.5)—

Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-0315",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver Process Integration(SAP_XIESR)",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.10 to 7.11"
            },
            {
              "status": "affected",
              "version": "< 7.20"
            },
            {
              "status": "affected",
              "version": "< 7.30"
            },
            {
              "status": "affected",
              "version": "< 7.31"
            },
            {
              "status": "affected",
              "version": "< 7.40"
            },
            {
              "status": "affected",
              "version": "< 7.50"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver Process Integration(SAP_XITOOL)",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.10 to 7.11"
            },
            {
              "status": "affected",
              "version": "< 7.30"
            },
            {
              "status": "affected",
              "version": "< 7.31"
            },
            {
              "status": "affected",
              "version": "< 7.40"
            },
            {
              "status": "affected",
              "version": "< 7.50"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver Process Integration(SAP_XIPCK)",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.10 to 7.11"
            },
            {
              "status": "affected",
              "version": "< 7.20"
            },
            {
              "status": "affected",
              "version": "< 7.30"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-06-12T17:29:03.747",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2755438",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2755438",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure."
    },
    {
      "lang": "es",
      "value": "Bajo ciertas condiciones, la interfaz de usuario web de PI Integration Builder de SAP NetWeaver Process Integration (versiones: SAP_XIESR: 7.10 a 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 a 7.11, 7.30, 7.31, 7.40, 7.50 y SAP_XIPCK 7.10 a 7.11, 7.20, 7.30) permite a un atacante acceder a las contraseñas utilizadas en los canales FTP que conducen a la divulgación de información."
    }
  ],
  "lastModified": "2026-06-17T02:08:09.960",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75E83C25-D30B-4459-A1F1-DE7EC9FD46BE"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "900D10B0-B47B-46B0-A0A9-8E41660429DD"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D57CEB9D-5C06-4B3E-A36E-5B8689CA5657"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3062CE84-B6E2-40DE-B7B1-0752FC21BFAD"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "587D81FB-B2ED-4184-9258-A38A18B36DC5"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A325699D-6AB0-4BBC-A21C-A974FA1612DE"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_process_integration:7.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A3A3226-28D1-4B43-942B-F41BD340E746"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}