CVE-2019-0318 describes an information disclosure vulnerability in specific versions of SAP NetWeaver Application Server for Java (Startup Framework), including versions 7.21, 7.22, 7.45, 7.49, and 7.53. This medium-severity flaw (CVSS 5.3) allows a low-privileged attacker to remotely access restricted information under certain conditions, with high impact on confidentiality. Despite its age, there is no known public exploit code or active exploitation, and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited external attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.21CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.21:*:*:*:*:*:*:* | ||
7.22CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.22:*:*:*:*:*:*:* | ||
7.45CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.45:*:*:*:*:*:*:* | ||
7.49CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.49:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.53:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.