VYPR

SAP_XIAF

by SAP

CVEs (2)

  • CVE-2023-37488MedAug 8, 2023
    risk 0.40cvss 6.1epss 0.00

    In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scripting (XSS) attack. On successful exploitation the attacker can cause limited impact on…

  • CVE-2019-0356MedSep 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.