CVE Published: 10/04/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: sap |
Vendor: SAP SE |
Product: SAP NetWeaver Process Integration (Runtime Workbench) Status : PUBLISHED
CVE-2019-0282 Description
Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Java package and Java object names which can be misused by the attacker.
CWE-ID: CWE Name: Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Java package and Java object names which can be misused by the attacker. Source: SAP SE
Common Attack Pattern Enumeration and Classification (CAPEC)