CVE-2019-0391: SAP NetWeaver Application Server Java

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.

Affected products

  • SAP NetWeaver Application Server Java: version 7.10 only; version 7.20 only; version 7.30 only; version 7.31 only; version 7.40 only; version 7.50 only

Published 2019-11-13. Last modified 2026-06-17.