CVE-2019-0391 is an information disclosure vulnerability in SAP NetWeaver AS Java, affecting versions 7.10 through 7.50, allowing authenticated attackers to access restricted information. With a CVSS score of 4.3 (MEDIUM), it requires low privileges and has a low impact on confidentiality, with no integrity or availability impact. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting low overall attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.10CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.10:*:*:*:*:*:*:* | ||
7.20CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.20:*:*:*:*:*:*:* | ||
7.30CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:* | ||
7.31CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:* | ||
7.40CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.