Vulnerabilities > SAP > Netweaver Process Integration > 7.31

DATE CVE VULNERABILITY TITLE RISK
2021-05-11 CVE-2021-27617 Resource Exhaustion vulnerability in SAP Netweaver Process Integration
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source.
network
low complexity
sap CWE-400
4.0
2021-05-11 CVE-2021-27618 Unrestricted Upload of File with Dangerous Type vulnerability in SAP Netweaver Process Integration
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source.
network
low complexity
sap CWE-434
4.0
2021-04-14 CVE-2021-27604 XXE vulnerability in SAP Netweaver Process Integration
In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP recommends to refer this note.
network
low complexity
sap CWE-611
4.0
2021-04-14 CVE-2021-27599 Information Exposure vulnerability in SAP Netweaver Process Integration
SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would otherwise be restricted.
network
low complexity
sap CWE-200
4.0
2019-09-10 CVE-2019-0356 Unspecified vulnerability in SAP Netweaver Process Integration 7.31/7.40/7.50
Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
4.0
2019-08-14 CVE-2019-0337 Cross-site Scripting vulnerability in SAP Netweaver Process Integration
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url thereby resulting in Reflected Cross-Site Scripting (XSS) vulnerability
network
sap CWE-79
4.3
2019-07-10 CVE-2019-0328 OS Command Injection vulnerability in SAP Netweaver Process Integration
ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights.
network
low complexity
sap CWE-78
critical
9.0
2019-06-14 CVE-2019-0316 Cross-site Scripting vulnerability in SAP Netweaver Process Integration
SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the victim is tricked to click on those malicious links, resulting in reflected Cross Site Scripting vulnerability.
network
sap CWE-79
3.5
2019-06-12 CVE-2019-0315 Unspecified vulnerability in SAP Netweaver Process Integration
Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure.
network
low complexity
sap
5.0
2019-06-12 CVE-2019-0312 Missing Authentication for Critical Function vulnerability in SAP Netweaver Process Integration
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected.
network
low complexity
sap CWE-306
5.0