cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2019-0316,https://securityvulnerability.io/vulnerability/CVE-2019-0316,,"SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the victim is tricked to click on those malicious links, resulting in reflected Cross Site Scripting vulnerability.",SAP,"SAP Netweaver Process Integration(SAP Xiesr),SAP Netweaver Process Integration(SAP Xitool)",4.8,MEDIUM,0.000539999979082495,false,false,false,false,,false,false,2019-06-14T18:50:55.000Z,0 CVE-2019-0312,https://securityvulnerability.io/vulnerability/CVE-2019-0312,,"Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of restrictive firewall and port settings.",SAP,"SAP Netweaver Process Integration(SAP Xiesr),SAP Netweaver Process Integration(SAP Xitool)",5.3,MEDIUM,0.0008999999845400453,false,false,false,false,,false,false,2019-06-12T16:11:08.000Z,0 CVE-2019-0315,https://securityvulnerability.io/vulnerability/CVE-2019-0315,,"Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure.",SAP,"SAP Netweaver Process Integration(SAP Xiesr),SAP Netweaver Process Integration(SAP Xitool),SAP Netweaver Process Integration(SAP Xipck)",7.5,HIGH,0.0017800000496208668,false,false,false,false,,false,false,2019-06-12T16:11:08.000Z,0 CVE-2019-0305,https://securityvulnerability.io/vulnerability/CVE-2019-0305,,"Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. Successful exploitation of this vulnerability leads to unwanted modification of user's data.",SAP,SAP Netweaver Process Integration(SAP Xiesr And SAP Xitool),4.3,MEDIUM,0.0008399999933317304,false,false,false,false,,false,false,2019-06-12T14:21:39.000Z,0