CVE-2019-0278
Summary
| CVE | CVE-2019-0278 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-10 21:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database tables used by the application, leading to information disclosure. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Process Integration | 7.10 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.11 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.20 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.30 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.31 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.40 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.50 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.10 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.11 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.20 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.30 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.31 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.40 | All | All | All |
| Application | Sap | Netweaver Process Integration | 7.50 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – April 2019 - Product Security Response at SAP - Community Wiki | CONFIRM | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | CONFIRM | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.