{"api_version":"1","generated_at":"2026-07-23T08:29:32+00:00","cve":"CVE-2019-0367","urls":{"html":"https://cve.report/CVE-2019-0367","api":"https://cve.report/api/cve/CVE-2019-0367.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-0367","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-0367"},"summary":{"title":"CVE-2019-0367","description":"SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check.","state":"PUBLIC","assigner":"cna@sap.com","published_at":"2019-10-08 20:15:00","updated_at":"2019-10-10 15:01:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://launchpad.support.sap.com/#/notes/2805777","name":"https://launchpad.support.sap.com/#/notes/2805777","refsource":"MISC","tags":["Permissions Required"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050","name":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"SAP Security Patch Day – October 2019 - Product Security Response at SAP - SCN Wiki","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-0367","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-0367","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"367","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"netweaver_process_integration","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"367","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"netweaver_process_integration","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"367","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"netweaver_process_integration","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"367","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"netweaver_process_integration","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-0367","ASSIGNER":"cna@sap.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"SAP SE","product":{"product_data":[{"product_name":"SAP NetWeaver Process Integration (B2B Toolkit)","version":{"version_data":[{"version_name":"<","version_value":"1.0"},{"version_name":"<","version_value":"2.0"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Missing Authorization Check"}]}]},"references":{"reference_data":[{"url":"https://launchpad.support.sap.com/#/notes/2805777","refsource":"MISC","name":"https://launchpad.support.sap.com/#/notes/2805777"},{"refsource":"CONFIRM","name":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050","url":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050"}]}},"nvd":{"publishedDate":"2019-10-08 20:15:00","lastModifiedDate":"2019-10-10 15:01:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:netweaver_process_integration:1.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:netweaver_process_integration:2.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"367","Ordinal":"136775","Title":"CVE-2019-0367","CVE":"CVE-2019-0367","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"367","Ordinal":"1","NoteData":"SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"367","Ordinal":"2","NoteData":"2019-10-08","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"367","Ordinal":"3","NoteData":"2019-10-08","Type":"Other","Title":"Modified"}]}}}