CVE-2019-0367

MEDIUM

SAP NetWeaver Process Integration - Missing Authorization Check for B2B Table Content Import

Title source: llm
STIX 2.1

Description

SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2805777

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-862
Status published
Products (2)
sap/netweaver_process_integration 1.0
sap/netweaver_process_integration 2.0
Published Oct 08, 2019
Tracked Since Feb 18, 2026