CVE-2019-0282 describes an authentication bypass vulnerability in several web pages of SAP NetWeaver Process Integration (Runtime Workbench), affecting versions 7.10 through 7.50. This flaw allows unauthenticated access to internal system data, including release information, Java package, and object names. With a CVSS score of 5.3 (Medium), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, potentially leading to information disclosure. The EPSS score is low, indicating a low probability of exploitation in the wild. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one article from SecurityWeek mentioning the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.10CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_process_integration:7.10:*:*:*:*:*:*:* | ||
7.11CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_process_integration:7.11:*:*:*:*:*:*:* | ||
7.30CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_process_integration:7.30:*:*:*:*:*:*:* | ||
7.31CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_process_integration:7.31:*:*:*:*:*:*:* | ||
7.40CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_process_integration:7.40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.