CVE-2019-0278: SAP NetWeaver Process Integration

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database tables used by the application, leading to information disclosure.

Affected products

  • SAP NetWeaver Process Integration: version 7.10 only; version 7.11 only; version 7.20 only; version 7.30 only; version 7.31 only; version 7.40 only; …

Published 2019-04-10. Last modified 2026-06-17.