CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality w...Show more |
In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scripting (XSS) attack. On successful exploi...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might acc...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might ac...Show more |
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming a...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Dec 13, 2022 N/A· v4 9.4 CRITICAL· v3 N/A· v2 An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 May 11, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a m...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 May 11, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicio...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would o...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Oct 8, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Auth...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Sep 10, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. |
1Sap 1Netweaver Process Integration Nov 21, 2024 Aug 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url the...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Jul 10, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the in...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Jun 14, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Jun 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_X...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Jun 12, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Jun 12, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that be...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 10, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML signatures and send arbitrary requests...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like relea...Show more |