VYPR

Process Integration

by SAP

CVEs (5)

  • CVE-2020-6305MedJan 14, 2020
    risk 0.40cvss 6.1epss 0.01

    PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2019-0379MedOct 8, 2019
    risk 0.35cvss 5.3epss 0.01

    SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check

  • CVE-2021-27618MedMay 11, 2021
    risk 0.32cvss 4.9epss 0.01

    The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the application, which could…

  • CVE-2021-27617MedMay 11, 2021
    risk 0.32cvss 4.9epss 0.01

    The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application,…

  • CVE-2020-26814MedNov 10, 2020
    risk 0.32cvss 4.9epss 0.01

    SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be used to read messages processed by the module leading to…