Netweaver Process Integration
Vendor:
First CVE: Apr 10, 2019 · Active for 7 years
21
Total CVEs
More Total CVEs than 94% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Netweaver Process Integration over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2019
7 years ago
Most Recent CVE
Mar 12, 2024
867 days ago
CVE Severity & Scoring
Netweaver Process Integration21 CVEs
76%
19%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (81.0%)
Unknown0 (0.0%)
Required4 (19.0%)
Privileges Required
Low6 (28.6%)
High4 (19.0%)
None11 (52.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41271CRITICAL An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make us | Dec 13, 2022 | 9.4 | 29 | NO | NO |
CVE-2022-41272HIGH An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - versi | Dec 13, 2022 | 8.6 | 28 | NO | NO |
CVE-2019-0328HIGH ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. | Jul 10, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-0315HIGH Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 t | Jun 12, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-0283HIGH SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML | Apr 10, 2019 | 7.1 | 23 | NO | NO |
CVE-2023-35873MEDIUM The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user ide | Jul 11, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-35872MEDIUM The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user id | Jul 11, 2023 | 6.5 | 20 | NO | NO |
CVE-2021-27604MEDIUM In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - | Apr 14, 2021 | 6.5 | 20 | NO | NO |
CVE-2021-27599MEDIUM SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information | Apr 14, 2021 | 6.5 | 20 | NO | NO |
CVE-2019-0312MEDIUM Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) | Jun 12, 2019 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Netweaver Process Integration
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.50 | 19 | 6.0 | 0.8% | 0 | 0 |
| 7.5 | 1 | 7.2 | 3.4% | 0 | 0 |
| 7.40 | 13 | 5.5 | 0.9% | 0 | 0 |
| 7.4 | 1 | 7.2 | 3.4% | 0 | 0 |
| 7.31 | 14 | 5.6 | 1.1% | 0 | 0 |
| 7.30 | 12 | 5.6 | 0.9% | 0 | 0 |
| 7.3 | 1 | 7.2 | 3.4% | 0 | 0 |
| 7.20 | 8 | 5.3 | 0.9% | 0 | 0 |
| 7.11 | 10 | 5.5 | 0.9% | 0 | 0 |
| 7.10 | 12 | 5.6 | 0.9% | 0 | 0 |
| 7.1 | 1 | 7.2 | 3.4% | 0 | 0 |
| 7.0 | 1 | 7.2 | 3.4% | 0 | 0 |
| 2.0 | 1 | 4.3 | 0.5% | 0 | 0 |
| 1.0 | 1 | 4.3 | 0.5% | 0 | 0 |